Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2023-36331 Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulatio… Xmall No fix yet Fix from $1,9502026-01-12 MEDIUM 6.1 CVE-2025-65540 Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as use… Xmall No fix yet Fix from $1,6002025-11-29 HIGH 8.8 CVE-2025-8527 A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file xboot-fa… Xboot after 3.3.4 Fix from $1,9502025-08-04 MEDIUM 5.9 CVE-2025-8528 A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/g… Xboot after 3.3.4 Fix from $1,6002025-08-04 CRITICAL 9.8 CVE-2025-8526 A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file x… Xboot after 3.3.4 Fix from $2,3002025-08-04 MEDIUM 5.3 CVE-2025-8525 A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring Bo… Xboot after 3.3.4 Fix from $1,6002025-08-04 CRITICAL 9.8 CVE-2025-45612 Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index. Xmall after 1.1 Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-28399 An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class. Xmall No fix yet Fix from $2,3002025-04-15 CRITICAL 9.8 CVE-2024-24112 xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. Xmall No fix yet Fix from $2,3002024-02-06 MEDIUM 6.1 CVE-2021-43432 A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp. Xmall after 2021-11-07 Fix from $1,6002022-04-07