Xmall
Vendor:
First CVE: Apr 7, 2022 · Active for 4 years
6
Total CVEs
More Total CVEs than 83% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xmall over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 7, 2022
4 years ago
Most Recent CVE
Jan 12, 2026
196 days ago
CVE Severity & Scoring
Xmall6 CVEs
33%
17%
50%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required2 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24112CRITICAL xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. | Feb 6, 2024 | 9.8 | 37 | NO | YES |
CVE-2025-45612CRITICAL Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index. | May 5, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-28399CRITICAL An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class. | Apr 15, 2025 | 9.8 | 27 | NO | NO |
CVE-2023-36331HIGH Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId | Jan 12, 2026 | 8.2 | 26 | NO | NO |
CVE-2021-43432MEDIUM A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp. | Apr 7, 2022 | 6.1 | 24 | NO | NO |
CVE-2025-65540MEDIUM Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are direc | Nov 29, 2025 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
16.7% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Xmall
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.1 | 4 | 8.5 | 1.1% | 0 | 1 |