Home/Product/fuyang lipengjun platform
Product

fuyang lipengjun platform

35 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-57213
all versions
Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive informa
7.5HIGH
CVE-2025-57212
all versions
Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information
7.5HIGH
CVE-2025-57210
all versions
Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive informatio
7.5HIGH
CVE-2025-10822
all versions
A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogController of the f
4.3MEDIUM
CVE-2025-10821
all versions
A flaw has been found in fuyang_lipengjun platform 1.0. The affected element is the function TopicCategoryController of the file /
4.3MEDIUM
CVE-2025-10820
all versions
A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /topic/queryAl
4.3MEDIUM
CVE-2025-10819
all versions
A security vulnerability has been detected in fuyang_lipengjun platform 1.0. This issue affects the function UserCouponController
4.3MEDIUM
CVE-2025-10676
all versions
A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /brand/query
4.3MEDIUM
CVE-2025-10675
all versions
A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of the file /a
4.3MEDIUM
CVE-2025-10674
all versions
A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController of the file
4.3MEDIUM
CVE-2025-10086
all versions
A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adpositio
6.3MEDIUM
CVE-2025-9936
all versions
A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/qu
4.3MEDIUM
CVE-2025-7936
all versions
A vulnerability has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a and classified as criti
6.3MEDIUM
CVE-2025-7935
<= 2025-06-29
A vulnerability, which was classified as critical, was found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea884
6.3MEDIUM
CVE-2025-7934
<= 2025-06-29
A vulnerability, which was classified as critical, has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842a
6.3MEDIUM
CVE-2025-1683
< 25.3
Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker w
7.8HIGH
CVE-2024-7211
all versions
The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, p
4.7MEDIUM
CVE-2023-50166
>= 8.5.4 and <= 8.8.3
Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
6.1MEDIUM
CVE-2023-50165
>= 8.2.1 and <= 23.1.0
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
8.5HIGH
CVE-2023-5964
< 23.0
The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does
9.9CRITICAL
CVE-2023-45163
< 18.1
The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properl
9.9CRITICAL
CVE-2023-45161
< 20.1
The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properl
9.9CRITICAL
CVE-2023-32089
>= 8.1.0 and <= 8.8.2
Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description
4.6MEDIUM
CVE-2023-32088
>= 8.1.0 and < 8.7.5
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation
4.6MEDIUM
CVE-2023-32087
>= 8.1.0 and < 8.7.5
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation
4.6MEDIUM
CVE-2023-45162
all versions
Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution. Application o
9.9CRITICAL
CVE-2023-36825
>= 14.0.1 and < 14.5.0
Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A
9.6CRITICAL
CVE-2020-27225
<= 4.18
In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local h
7.8HIGH
CVE-2020-15263
>= 9.0.0 and < 9.4.4
In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, th
8.0HIGH
CVE-2019-16374
<= 8.2.1
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker
9.8CRITICAL
CVE-2020-8775
< 8.2.6
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
8.9HIGH
CVE-2020-8773
< 8.2.6
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.
8.9HIGH
CVE-2004-0318
all versions
Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID o
CVE-2004-0317
all versions
Buffer overflow in eauth in Load Sharing Facility 4.x, 5.x, and 6.x allows local users or remote attackers within the LSF cluster
CVE-2003-0337
all versions
The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying
threatengine.sh