Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/yapi-vendor — 4 CVEs · VulnScope
pkg:npm/
yapi-vendor
4 total CVEs
HIGH
1
MEDIUM
3
✅ Check your installed version
Check
All known vulnerabilities
HIGH
7.4
CVE-2025-70058
yapi disables TLS/SSL certificate validation via rejectUnauthorized: false in Axios HTTPS agent
from 0, <= 1.12.0
MEDIUM
5.4
CVE-2021-36686
Cross-site Scripting in yapi-vendor
from 0, <= 1.9.1
MEDIUM
5.4
CVE-2018-17574
Cross-site Scripting in yapi-vendor
from 0, < 1.3.23
MEDIUM
5.1
Weak JSON Web Token in yapi-vendor
from 0, < 1.9.3
CVE-2021-27884