Linlinjava
Linlinjava Litemall: vulnerabilidades y CVE
Linlinjava Litemall tiene 16 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-90570 | Media (4.8) | 0.37% | — | 13 sept 2026 | A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component… |
| CVE-2026-90569 | Media (4.8) | 0.37% | — | 13 sept 2026 | A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin… |
| CVE-2026-8773 | Baja (2) | 0.41% | — | 18 may 2026 | A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java… |
| CVE-2026-8772 | Baja (2) | 0.33% | — | 18 may 2026 | A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admin Endpoint. Executing a manipulation can lead to sql injection. The attack can be executed… |
| CVE-2026-8771 | Media (5.5) | 0.41% | — | 18 may 2026 | A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxGoodsController.java of the component… |
| CVE-2025-10291 | Baja (2.1) | 0.34% | — | 12 sept 2025 | A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of the file /wx/aftersale/cancel. Executing manipulation of the argument ID can lead to improper… |
| CVE-2025-8991 | Baja (2.1) | 0.33% | — | 15 ago 2025 | A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file /admin/config/express of the component Business Logic Handler. The manipulation… |
| CVE-2025-8974 | Baja (2.9) | 0.53% | — | 14 ago 2025 | A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/util/JwtHelper.java of the… |
| CVE-2025-8965 | Baja (2.1) | 0.37% | — | 14 ago 2025 | A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file… |
| CVE-2025-8764 | Baja (2.1) | 0.25% | — | 9 ago 2025 | A vulnerability classified as critical has been found in linlinjava litemall up to 1.8.0. Affected is the function Upload of the file /wx/storage/upload. The manipulation of the argument File leads to unrestricted… |
| CVE-2025-8753 | Baja (2.1) | 0.51% | — | 9 ago 2025 | A vulnerability, which was classified as critical, has been found in linlinjava litemall up to 1.8.0. Affected by this issue is the function delete of the file /admin/storage/delete of the component File Handler. The… |
| CVE-2025-6702 | Baja (2.1) | 0.40% | — | 26 jun 2025 | A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment/post. The manipulation of the argument adminComment leads to improper… |
| CVE-2024-46382 | Alta (7.5) | 0.63% | — | 19 sept 2024 | A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminOrderController.java. |
| CVE-2024-6452 | Media (5.3) | 0.47% | — | 2 jul 2024 | A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file AdminGoodscontroller.java. The manipulation of the argument… |
| CVE-2024-24323 | Alta (7.2) | 0.72% | — | 27 feb 2024 | SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java… |
| CVE-2018-18434 | Alta (7.5) | 2.4% | — | 17 oct 2018 | An issue was discovered in litemall 0.9.0. Arbitrary file download is possible via ../ directory traversal in linlinjava/litemall/wx/web/WxStorageController.java in the litemall-wx-api component. |