exrick 漏洞與 CVE 列表(10)

產品(CPE): — CVE 數: 10

exrick 漏洞概覽

彙總 exrick 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。

已披露問題常與 SQL 注入、SSRF與路徑處理缺陷 相關,可能在 生產負載與軟體部署 場景中帶來 檔案覆寫與資料外洩 等暴露風險。

相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。

漏洞分布趨勢(近 24 個月)

顯示 11010 CVE 數
«« 第一頁 « 上一頁 第 1 / 1 頁 下一頁 »
CVE 摘要 來源 最高 CVSS EPSS % 公開時間 更新時間
CVE-2023-36331 Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId. [email protected] 8.2 0.21% 2026-01-12 2026-06-17
CVE-2025-65540 Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are directly rendered into HTML without proper sanitization or encoding, allowing attackers to inject and execute malicious scripts. [email protected] 6.1 0.15% 2025-11-28 2026-06-17
CVE-2025-8528 A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation leads to cleartext storage of sensitive information in a cookie. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. [email protected] 2.9 0.28% 2025-08-04 2026-06-17
CVE-2025-8527 A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file xboot-fast/src/main/java/cn/exrick/xboot/modules/base/controller/common/SecurityController.java of the component Swagger. The manipulation of the argument loginUrl leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. [email protected] 2.1 0.29% 2025-08-04 2026-06-17
CVE-2025-8526 A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file xboot-fast/src/main/java/cn/exrick/xboot/modules/base/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. [email protected] 2.1 0.31% 2025-08-04 2026-06-17
CVE-2025-8525 A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring Boot Admin/Spring Actuator. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. [email protected] 5.5 0.41% 2025-08-04 2026-06-17
CVE-2025-45612 Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index. [email protected] 9.8 0.45% 2025-05-05 2026-06-17
CVE-2025-28399 An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class. [email protected] 9.8 0.50% 2025-04-15 2026-06-17
CVE-2024-24112 xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. [email protected] 9.8 3.35% 2024-02-05 2026-06-17
CVE-2021-43432 A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp. [email protected] 6.1 0.80% 2022-04-07 2026-06-17
«« 第一頁 « 上一頁 第 1 / 1 頁 下一頁 »
cvelogic Threat Intelligence