Mini-Tmall是Mini-Tmall开源的一款基于 Spring Boot 的综合性 B2C 电商平台。用于搭建电商平台,提供商品交易服务。 Mini-Tmall 20250211及之前版本存在安全漏洞,该漏洞源于ProductMapper.java文件中的SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Mini-Tmall | 20250211 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-1890 | 6.3 MEDIUM | shishuocms ManageUpLoadAction.java handleRequest unrestricted upload |
| CVE-2025-1891 | 4.3 MEDIUM | shishuocms cross-site request forgery |
| CVE-2024-55064 | EasyVirt DC NetScope 跨站脚本漏洞 | |
| CVE-2025-25939 | Reprise Software Reprise License Manager 跨站脚本漏洞 | |
| CVE-2025-25967 | DDSN Interactive Acora CMS 跨站请求伪造漏洞 | |
| CVE-2025-26206 | storefront 跨站请求伪造漏洞 | |
| CVE-2024-51091 | Sea.js 跨站脚本漏洞 | |
| CVE-2023-49031 | Tikit 安全漏洞 | |
| CVE-2024-53384 | tsup 跨站脚本漏洞 | |
| CVE-2024-53388 | Mavo 跨站脚本漏洞 | |
| CVE-2024-53387 | UMeditor 跨站脚本漏洞 | |
| CVE-2024-57240 | Apryse WebViewer 跨站脚本漏洞 | |
| CVE-2024-55570 | Cubro EXA48200 安全漏洞 | |
| CVE-2025-25948 | Serosoft Solutions Academia Student Information System EagleR 安全漏洞 | |
| CVE-2025-25953 | Serosoft Solutions Academia Student Information System EagleR 安全漏洞 | |
| CVE-2025-25950 | Serosoft Solutions Academia Student Information System EagleR 安全漏洞 | |
| CVE-2025-25952 | Serosoft Solutions Academia Student Information System EagleR 安全漏洞 | |
| CVE-2025-25949 | Serosoft Solutions Academia Student Information System EagleR 跨站脚本漏洞 | |
| CVE-2025-25951 | Serosoft Solutions Academia Student Information System EagleR 安全漏洞 | |
| CVE-2025-27584 | Serosoft Solutions Academia Student Information System EagleR 跨站脚本漏洞 |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet