Exrick / Xmall
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-90571 | Exrick xmall Order Printing order-print.jsp cross site scripting | MEDIUM | 5.3 | Sep 13, 2026 |
| CVE-2023-36331 | Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the q… | HIGH | 8.2 | Jan 12, 2026 |
| CVE-2025-65540 | Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and… | MEDIUM | 6.1 | Nov 29, 2025 |
| CVE-2025-45612 | Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index. | CRITICAL | 9.8 | May 5, 2025 |
| CVE-2025-28399 | An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class. | CRITICAL | 9.8 | Apr 15, 2025 |
| CVE-2024-24112 | xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. | CRITICAL | 9.8 | Feb 6, 2024 |
| CVE-2021-43432 | A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp. | MEDIUM | 6.1 | Apr 7, 2022 |
Showing 1 to 7 of 7 CVEs