newbee-mall-plus是newbee-ltd开源的一个电商系统。 newbee-mall-plus 2.0.0版本存在安全漏洞,该漏洞源于对文件src/main/java/ltd/newbee/mall/controller/common/UploadController.java中参数File的错误操作,可能导致不受限制的上传。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | newbee-mall-plus | 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-15264 | 7.3 HIGH | FeehiCMS TimThumb timthumb.php server-side request forgery |
| CVE-2025-15244 | 3.7 LOW | PHPEMS Purchase Request race condition |
| CVE-2025-15242 | 3.1 LOW | PHPEMS Coupon race condition |
| CVE-2025-61557 | nixseparatedebuginfod 安全漏洞 | |
| CVE-2025-56332 | pangolin 安全漏洞 | |
| CVE-2025-50343 | MATIO 安全漏洞 | |
| CVE-2025-66823 | TrueConf Server 安全漏洞 | |
| CVE-2025-66835 | TrueConf Client 安全漏洞 | |
| CVE-2025-66824 | TrueConf Server 安全漏洞 | |
| CVE-2025-66848 | JD Cloud多款产品 安全漏洞 | |
| CVE-2025-66834 | TrueConf Server 安全漏洞 | |
| CVE-2025-66723 | inMusic Engine DJ 安全漏洞 | |
| CVE-2025-65409 | GNU Recutils 安全漏洞 | |
| CVE-2025-65411 | GNU Unrtf 安全漏洞 | |
| CVE-2025-65925 | Zeroheight 安全漏洞 |
No comments yet