Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

Youlai-mall 2.0.0 Exposes Data to Hackers via Unsecured SQL Query

CVE-2026-3287
Summary

An attacker can inject malicious code into Youlai-mall's product search function, potentially allowing them to access sensitive data. This is a serious issue because it could be exploited by hackers to steal or manipulate data. You should update to a fixed version of Youlai-mall as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
youlai youlai-mall 2.0.0 –
Original title
A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/controller/app/SpuC...
Original description
A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/controller/app/SpuController.java of the component App-side Product Pagination Endpoint. Performing a manipulation of the argument sortField/sort results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 6.5
nvd CVSS3.1 9.8
nvd CVSS4.0 5.3
Vulnerability type
CWE-74 Injection
CWE-89 SQL Injection
Published: 27 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026