Youlai is a modestly represented vendor focused on e-commerce and application framework products, with a concentrated portfolio that includes its mall and boot platform components alongside web UI tooling. Vulnerabilities affecting the vendor skew toward serious outcomes with an elevated share reaching critical severity, and recur persistently through access-control weakness classes including improper authorization, incorrect privilege assignment, and missing authorization checks that characterize the vendor's core platform architecture. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Youlai over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3287CRITICAL A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/co | Feb 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-55469CRITICAL Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend. | Nov 26, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-14085HIGH A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId lea | Dec 5, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-14051HIGH A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing man | Dec 4, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-14086HIGH A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1/members/openid/. The manipulation of the argument openid re | Dec 5, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-15085HIGH A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/c | Dec 25, 2025 | 8.1 | 26 | NO | NO |
CVE-2025-55471HIGH Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users. | Nov 26, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-66735HIGH youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users | Dec 22, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-14052MEDIUM A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The ma | Dec 5, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-66736HIGH youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity | Dec 22, 2025 | 7.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Youlai.
Media articles that mention a CVE ID that affects a product developed by Youlai — matched by CVE ID, not by vendor name.