📦 Newbee Mall

by Newbee Mall Project

🔍 What is Newbee Mall?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-26218

CRITICAL CVSS 9.8 Feb 12, 2026

CVE-2026-26218 allows unauthenticated attackers to gain administrative control of newbee-mall applications by using predictable default passwords on pre-seeded administrator accounts. This affects dep...

CVE-2022-27477

CRITICAL CVSS 9.8 Apr 10, 2022

CVE-2022-27477 is an arbitrary file upload vulnerability in Newbee-Mall v1.0.0 that allows authenticated attackers to upload malicious files via the admin goods edit interface. This affects all deploy...

CVE-2020-23448

CRITICAL CVSS 9.8 Jan 26, 2021

CVE-2020-23448 is an authentication bypass vulnerability in newbee-mall e-commerce platform that allows remote attackers to gain administrative privileges without valid credentials. The vulnerability ...

CVE-2024-48178

HIGH CVSS 8.1 Oct 28, 2024

CVE-2024-48178 is a Server-Side Request Forgery (SSRF) vulnerability in newbee-mall v1.0.0 that allows attackers to make the server send unauthorized requests to internal or external systems via the g...

CVE-2025-10422

MEDIUM CVSS 4.3 Sep 15, 2025

This vulnerability in newbee-mall's order status handler allows attackers to manipulate order numbers to bypass authorization checks. Remote attackers can potentially access or modify order informatio...