Vulnerabilidades en gz-yami
7 resultadosAnálisis Vexday
Gz-yami apresenta 7 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando risco recente e potencialmente em evolução. Embora nenhuma esteja sob exploração ativa conhecida (KEV), uma é crítica e a fraqueza dominante (CWE-306 - falta de autenticação) representa um vetor de acesso direto que merece atenção imediata. O padrão de divulgação concentrado recomenda monitoramento contínuo e priorização de patches.
CVE-2026-102364MEDIUMmall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin APIEPSS —CVE-2026-102361CRITICALmall4j through 4.0 Missing Authentication in Password Update EndpointEPSS —CVE-2026-102367MEDIUMmall4j through 4.0 Insufficient Session Expiration via Token RefreshEPSS —CVE-2026-102366LOWmall4j through 4.0 Unrestricted File Upload in Admin File EndpointsEPSS —CVE-2026-102363MEDIUMmall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order NumberEPSS —CVE-2026-102362MEDIUMmall4j through 4.0 Missing Authentication in Product Review DeletionEPSS —CVE-2026-102365HIGHmall4j through 4.0 Missing Authorization in Admin User Address EndpointsEPSS —