Zhangyanbo2007 maintains Youkefu, a customer-service and communication platform, with a narrow but recurring vulnerability surface centered on input handling, access control, and resource validation issues. The durable signal reflects typical risks in web-based application middleware: untrusted deserialization, path traversal, improper input validation, and cross-boundary access-control weaknesses that arise in systems handling user data and file operations. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zhangyanbo2007 over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3241CRITICAL A vulnerability, which was classified as problematic, was found in zhangyanbo2007 youkefu up to 4.2.0. This affects an unknown part of the file src/main/java/com/ukefu/webim/web/ha | Apr 4, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-3381CRITICAL A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown part of the file WebIMController.java of the component File Up | Apr 7, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-4258HIGH A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youkefu-master\src\main\java\com\uk | May 5, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-2997HIGH A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown function of the file /res/url. The manipulation of the argumen | Mar 31, 2025 | 8.8 | 23 | NO | NO |
CVE-2025-4260HIGH A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system | May 5, 2025 | 8.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zhangyanbo2007.
Media articles that mention a CVE ID that affects a product developed by Zhangyanbo2007 — matched by CVE ID, not by vendor name.