Mall
Vendor:
First CVE: Nov 22, 2024 · Active for 1 year
16
Total CVEs
More Total CVEs than 93% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mall over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 22, 2024
20 months ago
Most Recent CVE
Feb 7, 2026
171 days ago
CVE Severity & Scoring
Mall16 CVEs
13%
75%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (75.0%)
High4 (25.0%)
Unknown0 (0.0%)
User Interaction
None14 (87.5%)
Unknown0 (0.0%)
Required2 (12.5%)
Privileges Required
Low6 (37.5%)
High0 (0.0%)
None10 (62.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8191MEDIUM A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of the component | Jul 26, 2025 | 5.4 | 35 | NO | YES |
CVE-2026-25858CRITICAL macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitra | Feb 7, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-13443MEDIUM A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the ar | Nov 20, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-11619HIGH A vulnerability, which was classified as problematic, has been found in macrozheng mall up to 1.0.3. Affected by this issue is some unknown functionality of the component JWT Token | Nov 22, 2024 | 8.1 | 22 | NO | NO |
CVE-2025-13116MEDIUM A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder of the file /order/cancelUserOrder. Executing manipulation of | Nov 13, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-8741MEDIUM A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/login. | Aug 8, 2025 | 5.9 | 20 | NO | NO |
CVE-2025-13117MEDIUM A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability is the function cancelOrder of the file /order/cancelOrder. | Nov 13, 2025 | 5.3 | 19 | NO | NO |
CVE-2025-13115MEDIUM A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the component Order Details Handle | Nov 13, 2025 | 5.3 | 19 | NO | NO |
CVE-2025-8755MEDIUM A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberController.java of the component | Aug 9, 2025 | 5.3 | 19 | NO | NO |
CVE-2025-8750MEDIUM A vulnerability has been found in macrozheng mall up to 1.0.3 and classified as problematic. Affected by this vulnerability is the function Upload of the file /minio/upload of the | Aug 9, 2025 | 5.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.2% of CVEs· 97th percentile
ExploitDB
1 CVE
6.2% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Mall
Top CWEs
Versions
No cataloged versions.