Exrick maintains a narrow but notably represented portfolio of e-commerce and management products, chiefly XMall and XBoot, that handle customer data and administrative functions. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through access-control, input-validation, and sensitive-data-handling weaknesses that are characteristic of web-facing business applications, with a moderate tendency to acquire public exploit code. Defenders should prioritize assessment of Exrick products in customer-facing deployments and treat authentication and session-security controls as high-risk areas; current severity, exploitation, and coverage details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exrick over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24112CRITICAL xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. | Feb 6, 2024 | 9.8 | 37 | NO | YES |
CVE-2025-8526CRITICAL A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file xboot-fast/src/main/java/cn/exri | Aug 4, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-45612CRITICAL Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index. | May 5, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-28399CRITICAL An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class. | Apr 15, 2025 | 9.8 | 27 | NO | NO |
CVE-2023-36331HIGH Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId | Jan 12, 2026 | 8.2 | 26 | NO | NO |
CVE-2025-8527HIGH A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file xboot-fast/src/main/java/cn/exrick/xboo | Aug 4, 2025 | 8.8 | 25 | NO | NO |
CVE-2021-43432MEDIUM A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp. | Apr 7, 2022 | 6.1 | 24 | NO | NO |
CVE-2025-65540MEDIUM Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are direc | Nov 29, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-8528MEDIUM A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation le | Aug 4, 2025 | 5.9 | 21 | NO | NO |
CVE-2025-8525MEDIUM A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring Boot Admin/Spring Actuator. The m | Aug 4, 2025 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exrick.
Media articles that mention a CVE ID that affects a product developed by Exrick — matched by CVE ID, not by vendor name.