Skip to main content

Vendor/product archive

macrozheng / mall CVEs

Beta · best-effort

16 CVEs tagged to macrozheng / mall1 Critical, 0 High, 3 Medium, 12 Low, 0 Unrated.

CVE-2026-25858

Published Feb 7, 2026

macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitr…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-15118

Published Dec 28, 2025

A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of the file /member/address/update/ of the component Member Endp…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-13443

Published Nov 20, 2025

A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the a…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-13118

Published Nov 13, 2025

A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of the file /order/paySuccess. The manipulation of the argumen…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-13117

Published Nov 13, 2025

A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability is the function cancelOrder of the file /order/cancelOrder…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-13116

Published Nov 13, 2025

A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder of the file /order/cancelUserOrder. Executing manipulation o…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-13115

Published Nov 13, 2025

A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the component Order Details Handl…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-9836

Published Sep 2, 2025

A vulnerability was found in macrozheng mall up to 1.0.3. This vulnerability affects the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderI…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9835

Published Sep 2, 2025

A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument orderId l…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9514

Published Aug 27, 2025

A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak password requirement…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8755

Published Aug 9, 2025

A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberController.java of the componen…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8750

Published Aug 9, 2025

A vulnerability has been found in macrozheng mall up to 1.0.3 and classified as problematic. Affected by this vulnerability is the function Upload of the file /minio/upload of the…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8742

Published Aug 8, 2025

A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Admin Login. The manipu…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8741

Published Aug 8, 2025

A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/login.…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8191

Published Jul 26, 2025

A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of the component…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-11619

Published Nov 22, 2024

A vulnerability, which was classified as problematic, has been found in macrozheng mall up to 1.0.3. Affected by this issue is some unknown functionality of the component JWT Toke…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1