📦 Mall Swarm

by Macrozheng

🔍 What is Mall Swarm?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-14016

MEDIUM CVSS 5.4 Dec 4, 2025

This vulnerability in macrozheng mall-swarm allows unauthorized deletion of user read history records through improper authorization in the delete function. Attackers can remotely exploit this to dele...

CVE-2025-13117

MEDIUM CVSS 5.4 Nov 13, 2025

This vulnerability allows attackers to cancel orders without proper authorization in macrozheng mall-swarm and mall applications. Attackers can exploit this remotely by manipulating the orderId parame...

CVE-2025-13118

MEDIUM CVSS 6.3 Nov 13, 2025

This vulnerability in macrozheng mall-swarm and mall allows attackers to bypass authorization by manipulating the orderID parameter in the paySuccess function. Remote attackers can exploit this to acc...

CVE-2025-13114

MEDIUM CVSS 6.3 Nov 13, 2025

This vulnerability in macrozheng mall-swarm allows attackers to bypass authorization controls when manipulating the updateAttr function in the cart update endpoint. Attackers can exploit this remotely...

CVE-2025-13115

MEDIUM CVSS 4.3 Nov 13, 2025

This vulnerability allows unauthorized access to order details in macrozheng mall-swarm and mall applications. Attackers can manipulate the orderId parameter to view orders they shouldn't have access ...

CVE-2025-13116

MEDIUM CVSS 5.4 Nov 13, 2025

This vulnerability allows improper authorization in macrozheng mall-swarm and mall applications up to version 1.0.3. Attackers can manipulate the orderId parameter in the cancelUserOrder function to p...