Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MStore API – Create Native Android & iOS Apps On The Cloud — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in MStore API – Create Native Android & iOS Apps On The Cloud, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting MStore API, a cloud-based service enabling developers to build native Android and iOS applications. The collection covers a range of weakness types, including authentication flaws, input validation issues, and cross-platform compatibility risks discovered during testing or reported by the community, spanning from early implementation phases through recent updates. Readers can use this page to track the vendor's security advisories, understand the specific weakness classes impacting this product, and review its historical vulnerability patterns. It serves as a reference for developers assessing risk exposure, comparing mitigation strategies, and aligning their release cycles with the latest security patches available for the MStore API platform.

Vendor: inspireui

CVE ID Title CVSS Severity Published
CVE-2026-13447 MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery CWE-287 9.8 Critical 2026-09-05
CVE-2026-3568 MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update CWE-639 4.3 Medium 2026-04-09
CVE-2025-4683 MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation CWE-862 4.3 Medium 2025-05-27
CVE-2025-3438 MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation CWE-269 6.5 Medium 2025-05-02
CVE-2024-12042 MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting) CWE-434 5.4 Medium 2024-12-13
CVE-2024-11179 MStore API <= 4.15.7 - Authenticated (Subscriber+) SQL Injection CWE-89 6.5 Medium 2024-11-20
CVE-2024-8242 MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload CWE-434 4.3 Medium 2024-09-13
CVE-2024-8269 MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration CWE-284 7.3 High 2024-09-13
CVE-2024-7628 MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover CWE-288 8.1 High 2024-08-15
CVE-2024-6328 MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass CWE-288 9.8 Critical 2024-07-12
CVE-2023-3277 MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation CWE-288 9.8 Critical 2023-11-03
CVE-2023-3202 MStore API <= 3.9.6 - Cross-Site Request Forgery to Firebase Server Key Update CWE-352 4.3 Medium 2023-07-12
CVE-2023-3199 MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update CWE-352 4.3 Medium 2023-07-12
CVE-2023-3197 MStore API <= 4.0.1 - Unauthenticated SQL Injection CWE-89 9.8 Critical 2023-06-24
CVE-2023-3198 MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Status Update CWE-352 4.3 Medium 2023-06-14
CVE-2023-3201 MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update CWE-352 4.3 Medium 2023-06-14
CVE-2023-3200 MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Message Update CWE-352 4.3 Medium 2023-06-14
CVE-2023-3203 MStore API <= 3.9.6 - Cross-Site Request Forgery to Product Limit Update CWE-352 4.3 Medium 2023-06-14
CVE-2020-36713 MStore API <= 2.1.5 - Authentication Bypass CWE-288 9.8 Critical 2023-06-07
CVE-2023-2732 MStore API <= 3.9.2 - Authentication Bypass CWE-288 9.8 Critical 2023-05-25
CVE-2023-2733 MStore API <= 3.9.0 - Authentication Bypass CWE-288 9.8 Critical 2023-05-25
CVE-2023-2734 MStore API <= 3.9.1 - Authentication Bypass CWE-288 9.8 Critical 2023-05-25

All 22 known CVE vulnerabilities affecting MStore API – Create Native Android & iOS Apps On The Cloud with full Chinese analysis, references, and POCs where available.