Joovii develops web-based logistics and shipping software, with its observed vulnerability profile centered on the Sendle Shipping product and characterized by cross-site scripting weaknesses in web page generation. Treat this as a narrow vendor footprint rather than a broad pattern; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joovii over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62976MEDIUM Missing Authorization vulnerability in Joovii Sendle Shipping official-sendle-shipping-method allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sen | Oct 27, 2025 | 5.3 | 18 | NO | NO |
CVE-2023-45761MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Joovii Sendle Shipping Plugin plugin <= 5.13 versions. | Oct 25, 2023 | 6.1 | 18 | NO | NO |
CVE-2025-60139MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Joovii Sendle Shipping official-sendle-shipping-method allows Cross Site Request Forgery.This issue affects Sendle Shipping: from | Sep 26, 2025 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joovii.
Media articles that mention a CVE ID that affects a product developed by Joovii — matched by CVE ID, not by vendor name.