Macrozheng
Macrozheng Mall: vulnerabilidades y CVE
Macrozheng Mall tiene 22 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses13
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-82423 | Baja (2.1) | 0.44% | — | 29 ago 2026 | A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId… |
| CVE-2026-82364 | Baja (2.3) | 0.29% | — | 29 ago 2026 | A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component Order Submission. The manipulation leads to race condition. It is… |
| CVE-2026-79406 | Media (5.3) | 0.39% | — | 25 ago 2026 | A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity… |
| CVE-2026-19361 | Baja (2.9) | 0.44% | — | 9 ago 2026 | A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery.… |
| CVE-2026-15186 | Baja (2.1) | 0.41% | — | 9 jul 2026 | A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. The manipulation of the argument orderId leads to… |
| CVE-2026-10070 | Media (5.1) | 0.22% | — | 29 may 2026 | A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of the component Super Admin Password Handler. Performing a manipulation results in improper… |
| CVE-2026-25858 | Crítica (9.3) | 1.0% | — | 7 feb 2026 | macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a… |
| CVE-2025-15118 | Baja (2.1) | 0.26% | — | 28 dic 2025 | A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of the file /member/address/update/ of the component Member Endpoint. The manipulation leads to improper… |
| CVE-2025-13443 | Baja (2.1) | 0.23% | — | 20 nov 2025 | A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access… |
| CVE-2025-13118 | Baja (2.1) | 0.24% | — | 13 nov 2025 | A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderID results in improper… |
| CVE-2025-13117 | Baja (2.1) | 0.30% | — | 13 nov 2025 | A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability is the function cancelOrder of the file /order/cancelOrder. The manipulation of the argument… |
| CVE-2025-13116 | Baja (2.1) | 0.30% | — | 13 nov 2025 | A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder of the file /order/cancelUserOrder. Executing manipulation of the argument orderId can lead to… |
| CVE-2025-13115 | Baja (2.1) | 0.33% | — | 13 nov 2025 | A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the component Order Details Handler. Performing manipulation of the… |
| CVE-2025-9836 | Baja (2.1) | 0.30% | — | 2 sept 2025 | A vulnerability was found in macrozheng mall up to 1.0.3. This vulnerability affects the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderId results in authorization bypass. The… |
| CVE-2025-9835 | Baja (2.1) | 0.34% | — | 2 sept 2025 | A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument orderId leads to authorization bypass. The attack… |
| CVE-2025-9514 | Media (6.3) | 0.39% | — | 27 ago 2025 | A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak password requirements. The attack can be executed remotely.… |
| CVE-2025-8755 | Media (5.5) | 0.53% | — | 9 ago 2025 | A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberController.java of the component com.macro.mall.portal.controller. The… |
| CVE-2025-8750 | Baja (1.9) | 0.28% | — | 9 ago 2025 | A vulnerability has been found in macrozheng mall up to 1.0.3 and classified as problematic. Affected by this vulnerability is the function Upload of the file /minio/upload of the component Add Product Page. The… |
| CVE-2025-8742 | Media (6.3) | 0.57% | — | 8 ago 2025 | A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Admin Login. The manipulation leads to improper restriction of… |
| CVE-2025-8741 | Baja (2.9) | 0.37% | — | 8 ago 2025 | A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/login. The manipulation leads to cleartext… |
| CVE-2025-8191 | Baja (2) | 1.7% | — | 26 jul 2025 | A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the… |
| CVE-2024-11619 | Baja (2.3) | 0.73% | — | 22 nov 2024 | A vulnerability, which was classified as problematic, has been found in macrozheng mall up to 1.0.3. Affected by this issue is some unknown functionality of the component JWT Token Handler. The manipulation leads to use… |