PT-2025-39561 · Yaycommerce · Yaycurrency

Nabil Irawan

·

Published

2025-09-26

·

Updated

2025-09-26

·

CVE-2025-60114

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions YayCommerce YayCurrency versions through 3.2
Description A code injection issue exists in YayCommerce YayCurrency. The flaw is due to improper control of code generation. Successful exploitation could allow attackers to inject and execute arbitrary code.
Recommendations Update YayCommerce YayCurrency to a version later than 3.2.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-60114

Affected Products

Yaycurrency