📦 Mall

by Macrozheng

🔍 What is Mall?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25858

CRITICAL CVSS 9.8 Feb 7, 2026

This vulnerability allows unauthenticated attackers to reset passwords for any user account by exploiting a flawed OTP verification process in the password reset workflow. Attackers only need a victim...

CVE-2025-15118

MEDIUM CVSS 4.3 Dec 28, 2025

This vulnerability allows unauthorized modification of member address data in macrozheng mall versions up to 1.0.3. Attackers can exploit improper authorization in the /member/address/update/ endpoint...

CVE-2025-13443

MEDIUM CVSS 5.4 Nov 20, 2025

This vulnerability in macrozheng mall allows attackers to bypass access controls and delete user read history records without proper authorization. Remote exploitation is possible, affecting all users...

CVE-2025-13117

MEDIUM CVSS 5.4 Nov 13, 2025

This vulnerability allows attackers to cancel orders without proper authorization in macrozheng mall-swarm and mall applications. Attackers can exploit this remotely by manipulating the orderId parame...

CVE-2025-13118

MEDIUM CVSS 6.3 Nov 13, 2025

This vulnerability in macrozheng mall-swarm and mall allows attackers to bypass authorization by manipulating the orderID parameter in the paySuccess function. Remote attackers can exploit this to acc...

CVE-2025-13115

MEDIUM CVSS 4.3 Nov 13, 2025

This vulnerability allows unauthorized access to order details in macrozheng mall-swarm and mall applications. Attackers can manipulate the orderId parameter to view orders they shouldn't have access ...

CVE-2025-13116

MEDIUM CVSS 5.4 Nov 13, 2025

This vulnerability allows improper authorization in macrozheng mall-swarm and mall applications up to version 1.0.3. Attackers can manipulate the orderId parameter in the cancelUserOrder function to p...

CVE-2025-9835

MEDIUM CVSS 4.3 Sep 2, 2025

This vulnerability allows attackers to bypass authorization checks in the cancelOrder function of macrozheng mall. By manipulating the orderId parameter, unauthorized users can cancel orders they shou...

CVE-2025-9836

MEDIUM CVSS 4.3 Sep 2, 2025

This vulnerability allows remote attackers to bypass authorization in the macrozheng mall e-commerce platform by manipulating the orderId parameter in the paySuccess function. Attackers could potentia...

CVE-2025-8755

MEDIUM CVSS 5.3 Aug 9, 2025

This vulnerability allows remote attackers to bypass authorization checks in the macrozheng mall e-commerce platform by manipulating the orderId parameter. Attackers could potentially access other use...

CVE-2024-11619

MEDIUM CVSS 5.0 Nov 22, 2024

This vulnerability in macrozheng mall's JWT Token Handler allows attackers to forge authentication tokens by exploiting the use of a default cryptographic key. Systems running affected versions could ...