Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

macrozheng — Vulnerabilities & Security Advisories 24

Browse all 24 CVE security advisories affecting macrozheng. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Macrozheng is an open-source project primarily used for building microservices and cloud-native applications. Historically, it has been associated with multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues. The project has recorded 18 CVEs, with several critical RCE vulnerabilities allowing attackers to execute arbitrary code through insecure deserialization or improper input validation. While no major public security incidents have been documented, the consistent pattern of vulnerabilities in authentication and access control components suggests potential risks for deployments without proper hardening. The project's widespread adoption in enterprise environments makes security updates particularly important for affected organizations.

Found 18 results / 24 Clear Filters
Top products by macrozheng: mall mall-swarm
CVE ID Title CVSS Severity Published
CVE-2026-82423 macrozheng mall Payment Status Endpoint paySuccess behavioral workflow — mall CWE-841 5.4 Medium 2026-08-29
CVE-2026-82364 macrozheng mall Order Submission submit race condition — mall CWE-362 4.2 Medium 2026-08-29
CVE-2026-79406 macrozheng mall quantity OmsCartItemServiceImpl.updateQuantity logic error — mall CWE-840 4.3 Medium 2026-08-25
CVE-2026-19361 macrozheng mall mall-portal getAuthCode password recovery — mall CWE-640 3.7 Low 2026-08-09
CVE-2026-15186 macrozheng mall Portal Endpoint create resource injection — mall CWE-99 6.3 Medium 2026-07-09
CVE-2026-10070 macrozheng mall Super Admin Password update improper authorization — mall CWE-285 4.7 Medium 2026-05-29
CVE-2026-25858 macrozheng mall <= 1.0.3 Unauthenticated Password Reset via OTP Disclosure — mall CWE-640 9.1 Critical 2026-02-07
CVE-2025-15118 macrozheng mall Member Endpoint update improper authorization — mall CWE-285 4.3 Medium 2025-12-28
CVE-2025-13443 macrozheng mall delete access control — mall CWE-284 5.4 Medium 2025-11-20
CVE-2025-9836 macrozheng mall paySuccess authorization — mall CWE-639 4.3 Medium 2025-09-02
CVE-2025-9835 macrozheng mall cancelUserOrder cancelOrder authorization — mall CWE-639 4.3 Medium 2025-09-02
CVE-2025-9514 macrozheng mall Registration weak password — mall CWE-521 3.7 Low 2025-08-27
CVE-2025-8755 macrozheng mall com.macro.mall.portal.controller UmsMemberController.java detail authorization — mall CWE-639 5.3 Medium 2025-08-09
CVE-2025-8750 macrozheng mall Add Product Page upload cross site scripting — mall CWE-79 2.4 Low 2025-08-09
CVE-2025-8742 macrozheng mall Admin Login excessive authentication — mall CWE-307 3.7 Low 2025-08-08
CVE-2025-8741 macrozheng mall login cleartext transmission — mall CWE-319 3.7 Low 2025-08-08
CVE-2025-8191 macrozheng mall Swagger UI index.html cross site scripting — mall CWE-79 3.5 Low 2025-07-26
CVE-2024-11619 macrozheng mall JWT Token default key — mall CWE-1394 5.0 Medium 2024-11-22

This page lists every published CVE security advisory associated with macrozheng. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.