Mercari's vulnerability profile centers on its e-commerce marketplace platform, a consumer-facing service handling user authentication and transaction workflows. The observed weakness classes reflect access-control issues, particularly missing authorization checks that affect the integrity of user account and transaction boundaries. Current exposure counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mercari over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-5604HIGH Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java R | Jul 9, 2020 | 8.1 | 26 | NO | NO |
CVE-2021-20835HIGH Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan version) versions prior to 4.49 | Nov 24, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-23388MEDIUM Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary we | Jan 26, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mercari.
Media articles that mention a CVE ID that affects a product developed by Mercari — matched by CVE ID, not by vendor name.