VendorsNewbee-Mall Projectnewbee-mallany version
Vulnerabilities

Newbee-Mall Project Newbee-Mall any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2019-19113
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.
Published 2019-11-18 · Modified
9.8EPSS 0.018
CVE-2020-23448
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.
Published 2021-01-26 · Modified
9.8EPSS 0.016
CVE-2026-26218
newbee-mall Default Seeded Administrator Credentials Allow Account Takeover
Published 2026-02-12 · Analyzed
9.8EPSS 0.006
CVE-2026-26219
newbee-mall Unsalted MD5 Password Hashing Enables Offline Credential Cracking
Published 2026-02-12 · Analyzed
9.3EPSS 0.003
CVE-2020-23449
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.
Published 2021-01-26 · Modified
7.5EPSS 0.009
CVE-2023-30216
Insecure permissions in the updateUserInfo function of newbee-mall before commit 1f2c2dfy allows attackers to obtain user account information.
Published 2023-05-04 · Modified
5.4EPSS 0.003
CVE-2025-10422
newbee-mall Order Status paySuccess improper authorization
Published 2025-09-15 · Analyzed
4.3EPSS 0.003