Ywoa Yimihome Ywoa

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Yimihome Ywoa.

By the Year

In 2026 there have been 0 vulnerabilities in Yimihome Ywoa. Last year, in 2025 Ywoa had 5 security vulnerabilities published. Right now, Ywoa is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 5 8.50
2024 0 0.00
2023 0 0.00
2022 3 9.47

It may take a day or so for new Ywoa vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Yimihome Ywoa Security Vulnerabilities

ywoa SQLi in AddressDao.xml before 2024.07.04 (critical)
CVE-2025-1227 8.8 - High - February 12, 2025

A vulnerability was found in ywoa up to 2024.07.03. It has been rated as critical. This issue affects the function selectList of the file com/cloudweb/oa/mapper/xml/AddressDao.xml. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

SQL Injection

Critical Improper Auth in ywoa <2024.07.04 via /oa/setup/setup.jsp
CVE-2025-1226 9.8 - Critical - February 12, 2025

A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

AuthZ

XML External Entity in ywoa WXCallBack extract leads to remote code exec
CVE-2025-1225 6.3 - Medium - February 12, 2025

A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

XXE

SQLi in ywoa (v<2024.07.04) via listNameBySql in UserMapper.xml
CVE-2025-1224 8.8 - High - February 12, 2025

A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listNameBySql of the file com/cloudweb/oa/mapper/xml/UserMapper.xml. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

SQL Injection

ywoa critical SQLi via sort arg in OaNoticeMapper up to 2024.07.03
CVE-2025-1216 8.8 - High - February 12, 2025

A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the function selectNoticeList of the file com/cloudweb/oa/mapper/xml/OaNoticeMapper.xml. The manipulation of the argument sort leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

SQL Injection

SQL Injection in ywoa v6.1 via exportExcel.do
CVE-2022-38808 8.8 - High - September 16, 2022

ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.

SQL Injection

Yimioa v6.1 SQLi via orderby GET parameter
CVE-2022-36605 9.8 - Critical - August 19, 2022

Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.

SQL Injection

Ywoa <=6.1 SQLi via /oa/setup/checkPool
CVE-2022-36606 9.8 - Critical - August 19, 2022

Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Yimihome Ywoa or by Yimihome? Click the Watch button to subscribe.

Yimihome
Vendor

Yimihome Ywoa
Product

subscribe