Critical
Low
Medium
CVE-2025-56161
Overview
YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the related User model without field filtering; because User.php defines no $hidden or $visible attributes, sensitive fields (bcrypt password hash, mobile numb...
Critical
Low
Medium
No items found.