Vulnerabilities in macrozheng

24 results
Vexday analysis

A macrozheng apresenta um perfil de risco moderado com 20 vulnerabilidades catalogadas, nenhuma delas sob exploração ativa conhecida. Embora apenas 1 seja crítica, a fraqueza dominante (CWE-285 - Autorização Imprópria) sugere problemas estruturais no controle de acesso. O risco é potencializado por 2 novos registros nos últimos 90 dias, indicando exposição contínua que requer monitoramento.

CVE-2025-8191MEDIUMmacrozheng mall Swagger UI index.html cross site scriptingEPSS 1.7%CVE-2026-25858CRITICALmacrozheng mall <= 1.0.3 Unauthenticated Password Reset via OTP DisclosureEPSS 1.0%CVE-2024-11619LOWmacrozheng mall JWT Token default keyEPSS 0.7%CVE-2025-8742MEDIUMmacrozheng mall Admin Login excessive authenticationEPSS 0.6%CVE-2025-8755MEDIUMmacrozheng mall com.macro.mall.portal.controller UmsMemberController.java detail authorizationEPSS 0.5%CVE-2026-19361MEDIUMmacrozheng mall mall-portal getAuthCode password recoveryEPSS 0.4%CVE-2026-82423MEDIUMmacrozheng mall Payment Status Endpoint paySuccess behavioral workflowEPSS 0.4%CVE-2026-15186MEDIUMmacrozheng mall Portal Endpoint create resource injectionEPSS 0.4%CVE-2025-9514MEDIUMmacrozheng mall Registration weak passwordEPSS 0.4%CVE-2026-79406MEDIUMmacrozheng mall quantity OmsCartItemServiceImpl.updateQuantity logic errorEPSS 0.4%CVE-2025-8741MEDIUMmacrozheng mall login cleartext transmissionEPSS 0.4%CVE-2025-9835MEDIUMmacrozheng mall cancelUserOrder cancelOrder authorizationEPSS 0.3%CVE-2025-13115MEDIUMmacrozheng mall-swarm/mall Order Details detail improper authorizationEPSS 0.3%CVE-2025-13117MEDIUMmacrozheng mall-swarm/mall cancelOrder improper authorizationEPSS 0.3%CVE-2025-13116MEDIUMmacrozheng mall-swarm/mall cancelUserOrder improper authorizationEPSS 0.3%CVE-2025-9836MEDIUMmacrozheng mall paySuccess authorizationEPSS 0.3%CVE-2025-14016MEDIUMmacrozheng mall-swarm delete improper authorizationEPSS 0.3%CVE-2026-82364LOWmacrozheng mall Order Submission submit race conditionEPSS 0.3%CVE-2025-8750MEDIUMmacrozheng mall Add Product Page upload cross site scriptingEPSS 0.3%CVE-2025-15118MEDIUMmacrozheng mall Member Endpoint update improper authorizationEPSS 0.3%