📦 Litemall

by Linlinjava

🔍 What is Litemall?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-46382

HIGH CVSS 7.5 Sep 19, 2024

A SQL injection vulnerability in litemall 1.8.0 allows remote attackers to execute arbitrary SQL commands through the goodsId, goodsSn, and name parameters in AdminGoodsController.java. This can lead ...

CVE-2024-24323

HIGH CVSS 7.2 Feb 27, 2024

This SQL injection vulnerability in litemall v1.8.0 allows remote attackers to execute arbitrary SQL commands through the AdminOrderController component. Attackers can potentially access, modify, or d...

CVE-2025-10291

MEDIUM CVSS 6.3 Sep 12, 2025

This vulnerability in linlinjava litemall up to version 1.8.0 allows remote attackers to bypass authorization controls via manipulation of the ID parameter in the WxAftersaleController function. Attac...

CVE-2025-8991

MEDIUM CVSS 4.3 Aug 15, 2025

A business logic vulnerability in linlinjava litemall up to version 1.8.0 allows remote attackers to manipulate the 'litemall_express_freight_min' parameter in the /admin/config/express endpoint, caus...

CVE-2025-8764

MEDIUM CVSS 6.3 Aug 9, 2025

This critical vulnerability in linlinjava litemall allows remote attackers to upload arbitrary files without restrictions via the /wx/storage/upload endpoint. Attackers can exploit this to upload mali...

CVE-2025-8753

MEDIUM CVSS 5.4 Aug 9, 2025

This critical vulnerability in litemall allows attackers to perform path traversal attacks via the delete function in the file handler component. Remote attackers can manipulate the 'key' parameter to...

CVE-2025-6702

MEDIUM CVSS 4.3 Jun 26, 2025

This is a mass assignment vulnerability in Litemall 1.8.0 that allows unauthorized manipulation of adminComment parameters. Attackers can exploit this remotely to potentially modify comment data with ...