VendorsNewbee-Mall Projectnewbee-mall1.0
Vulnerabilities

Newbee-Mall Project Newbee-Mall 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-27477
Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.
Published 2022-04-10 · Modified
9.8EPSS 0.011
CVE-2025-4259
newbee-mall UploadController.java upload unrestricted upload
Published 2025-05-05 · Analyzed
9.8EPSS 0.005
CVE-2024-48178
newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.
Published 2024-10-28 · Analyzed
8.1EPSS 0.003
CVE-2020-23447
newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".
Published 2021-01-26 · Modified
6.1EPSS 0.007
CVE-2025-1114
newbee-mall Add Category Page save cross site scripting
Published 2025-02-07 · Analyzed
5.4EPSS 0.003
CVE-2025-10423
newbee-mall kaptcha mallKaptcha Captcha
Published 2025-09-15 · Analyzed
3.7EPSS 0.005