VendorsGhostxbhuzy-ssm-mall1.1.0
Vulnerabilities

Ghostxbh Uzy-ssm-mall 1.1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-60834
A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input.
Published 2025-10-08 · Analyzed
6.5EPSS 0.004
CVE-2025-60833
An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data.
Published 2025-10-08 · Analyzed
6.5EPSS 0.004