Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mall — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in Mall, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the Mall software product, categorized by vendor, specific weakness type, and relevant tag. It compiles a comprehensive dataset of reported security flaws, covering incidents and advisories from January 1, 2018, through December 31, 2023. The collection includes various vulnerability classes such as cross-site scripting, injection flaws, broken access control, and security misconfigurations. Readers can utilize this resource to track a vendor's advisories and observe how they address issues over time. Users may also understand a specific weakness class by analyzing frequency and impact across different implementations. Additionally, the page allows for looking up a product's vulnerability history to assess long-term security posture and remediation trends. This information supports security researchers, developers, and organizational risk managers in making informed decisions about software procurement and patch management. By centralizing these data points, the page facilitates deeper analysis of how similar products are affected by the same classes of weaknesses. It serves as a neutral reference for evaluating the security lifecycle of the Mall product family without offering opinions or recommendations. All entries are sourced from public vulnerability databases and vendor notifications to ensure accuracy and traceability.

Vendor: Weitong

CVE ID Title CVSS Severity Published
CVE-2026-79406 macrozheng mall quantity OmsCartItemServiceImpl.updateQuantity logic error CWE-840 4.3 Medium 2026-08-25
CVE-2026-19361 macrozheng mall mall-portal getAuthCode password recovery CWE-640 3.7 Low 2026-08-09
CVE-2026-15186 macrozheng mall Portal Endpoint create resource injection CWE-99 6.3 Medium 2026-07-09
CVE-2026-10070 macrozheng mall Super Admin Password update improper authorization CWE-285 4.7 Medium 2026-05-29
CVE-2026-25858 macrozheng mall <= 1.0.3 Unauthenticated Password Reset via OTP Disclosure CWE-640 9.1 Critical 2026-02-07
CVE-2025-15118 macrozheng mall Member Endpoint update improper authorization CWE-285 4.3 Medium 2025-12-28
CVE-2025-13443 macrozheng mall delete access control CWE-284 5.4 Medium 2025-11-20
CVE-2025-9836 macrozheng mall paySuccess authorization CWE-639 4.3 Medium 2025-09-02
CVE-2025-9835 macrozheng mall cancelUserOrder cancelOrder authorization CWE-639 4.3 Medium 2025-09-02
CVE-2025-9514 macrozheng mall Registration weak password CWE-521 3.7 Low 2025-08-27
CVE-2025-8755 macrozheng mall com.macro.mall.portal.controller UmsMemberController.java detail authorization CWE-639 5.3 Medium 2025-08-09
CVE-2025-8750 macrozheng mall Add Product Page upload cross site scripting CWE-79 2.4 Low 2025-08-09
CVE-2025-8742 macrozheng mall Admin Login excessive authentication CWE-307 3.7 Low 2025-08-08
CVE-2025-8741 macrozheng mall login cleartext transmission CWE-319 3.7 Low 2025-08-08
CVE-2025-8191 macrozheng mall Swagger UI index.html cross site scripting CWE-79 3.5 Low 2025-07-26
CVE-2025-4136 Weitong Mall Sale Endpoint improper authorization CWE-285 5.4 Medium 2025-04-30
CVE-2025-4119 Weitong Mall Product Statistics queryTotal access control CWE-284 5.3 Medium 2025-04-30
CVE-2025-4118 Weitong Mall Product History historyList access control CWE-284 5.3 Medium 2025-04-30
CVE-2024-11619 macrozheng mall JWT Token default key CWE-1394 5.0 Medium 2024-11-22
CVE-2022-4961 Weitong Mall OrderDao.xml sql injection CWE-89 5.5 Medium 2024-01-12

All 20 known CVE vulnerabilities affecting Mall with full Chinese analysis, references, and POCs where available.