VendorsNewbee-Mall Projectnewbee-mallall versions
Vulnerabilities

Newbee-Mall Project Newbee-Mall

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2019-19113
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.
Published 2019-11-18 · Modified
9.8EPSS 0.018
CVE-2020-23448
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.
Published 2021-01-26 · Modified
9.8EPSS 0.016
CVE-2022-27477
Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.
Published 2022-04-10 · Modified
9.8EPSS 0.011
CVE-2026-26218
newbee-mall Default Seeded Administrator Credentials Allow Account Takeover
Published 2026-02-12 · Analyzed
9.8EPSS 0.006
CVE-2025-4259
newbee-mall UploadController.java upload unrestricted upload
Published 2025-05-05 · Analyzed
9.8EPSS 0.005
CVE-2026-26219
newbee-mall Unsalted MD5 Password Hashing Enables Offline Credential Cracking
Published 2026-02-12 · Analyzed
9.3EPSS 0.003
CVE-2024-48178
newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.
Published 2024-10-28 · Analyzed
8.1EPSS 0.003
CVE-2020-23449
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.
Published 2021-01-26 · Modified
7.5EPSS 0.009
CVE-2020-23447
newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".
Published 2021-01-26 · Modified
6.1EPSS 0.007
CVE-2022-27476
A cross-site scripting (XSS) vulnerability at /admin/goods/update in Newbee-Mall v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the goodsName parameter.
Published 2022-04-10 · Modified
6.1EPSS 0.006
CVE-2025-1114
newbee-mall Add Category Page save cross site scripting
Published 2025-02-07 · Analyzed
5.4EPSS 0.003
CVE-2023-30216
Insecure permissions in the updateUserInfo function of newbee-mall before commit 1f2c2dfy allows attackers to obtain user account information.
Published 2023-05-04 · Modified
5.4EPSS 0.003
CVE-2025-10422
newbee-mall Order Status paySuccess improper authorization
Published 2025-09-15 · Analyzed
4.3EPSS 0.003
CVE-2025-10423
newbee-mall kaptcha mallKaptcha Captcha
Published 2025-09-15 · Analyzed
3.7EPSS 0.005