Known Vulnerabilities for Mall4j by Gz-yami
Listed below are 7 of the newest known vulnerabilities associated with "Mall4j" by "Gz-yami".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-102367 json | mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to vali... | Not Provided | 2026-09-29 | 2026-09-28 |
| CVE-2026-102366 json | mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization che... | Not Provided | 2026-09-29 | 2026-09-28 |
| CVE-2026-102365 json | mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer addres... | Not Provided | 2026-09-29 | 2026-09-28 |
| CVE-2026-102364 json | mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as... | Not Provided | 2026-09-29 | 2026-09-28 |
| CVE-2026-102363 json | mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allo... | Not Provided | 2026-09-29 | 2026-09-28 |
| CVE-2026-102362 json | mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthe... | Not Provided | 2026-09-29 | 2026-09-28 |
| CVE-2026-102361 json | mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenti... | Not Provided | 2026-09-29 | 2026-09-28 |