Ghostxbh maintains a narrowly scoped e-commerce and service-management platform (the Uzy SSM Mall product line) where its vulnerability disclosures skew strongly toward critical-severity outcomes. The exposure recurs through web-application weakness classes including cross-site request forgery, cross-site scripting, code injection, improper access control, and untrusted deserialization—flaws that reflect the authentication and input-handling demands of user-facing enterprise software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ghostxbh over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3559CRITICAL A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the function ForeProductListController of the file /mall/produc | Apr 14, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-3558CRITICAL A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uploadUserHeadImage. The manipulati | Apr 14, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-60834MEDIUM A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input. | Oct 8, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-60833MEDIUM An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data. | Oct 8, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-3561MEDIUM A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forge | Apr 14, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-3560MEDIUM A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0 and classified as problematic. This issue affects some unknown processing of the file /product. The manipulation of the arg | Apr 14, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ghostxbh.
Media articles that mention a CVE ID that affects a product developed by Ghostxbh — matched by CVE ID, not by vendor name.