Project Team maintains a demonstration and commerce-related product line, with notable exposure concentrated in products such as TMall Demo and Mini-TMall that skews toward serious severity outcomes. The recurring vulnerability pattern centers on web application and code-execution weaknesses—unrestricted file uploads, code injection, cross-site scripting, SQL injection, and improper access control—that are characteristic of e-commerce platforms handling user input and dynamic content generation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Project Team over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8568CRITICAL A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manip | Sep 8, 2024 | 9.8 | 29 | NO | NO |
CVE-2025-1843CRITICAL A vulnerability, which was classified as critical, has been found in Mini-Tmall up to 20250211. This issue affects the function select of the file com/xq/tmall/dao/ProductMapper.ja | Mar 3, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-5132HIGH A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknown processing of the file tmall/admin/account/logout. The man | May 24, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-5131HIGH A vulnerability was found in Tmall Demo up to 20250505. It has been declared as critical. This vulnerability affects the function uploadCategoryImage of the file tmall/admin/upload | May 24, 2025 | 7.2 | 21 | NO | NO |
CVE-2025-5130HIGH A vulnerability was found in Tmall Demo up to 20250505. It has been classified as critical. This affects the function uploadProductImage of the file tmall/admin/uploadProductImage. | May 24, 2025 | 7.2 | 21 | NO | NO |
CVE-2024-40560HIGH Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability. | Jul 15, 2024 | 7.3 | 21 | NO | NO |
CVE-2025-5135MEDIUM A vulnerability, which was classified as problematic, has been found in Tmall Demo up to 20250505. Affected by this issue is some unknown functionality of the file /tmall/admin/ of | May 24, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-5134MEDIUM A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an unknown functionality of the component Buy Item Page. The man | May 24, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-5133MEDIUM A vulnerability classified as problematic has been found in Tmall Demo up to 20250505. Affected is an unknown function of the component Search Box. The manipulation leads to cross | May 24, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-40554HIGH An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information. | Jul 15, 2024 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Project Team.
Media articles that mention a CVE ID that affects a product developed by Project Team — matched by CVE ID, not by vendor name.