gz-yami mall4j

7 known vulnerabilities in gz-yami mall4j, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-102367 CVSS 5.3 medium mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the…
  • CVE-2026-102366 CVSS 2.1 low mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and…
  • CVE-2026-102365 CVSS 7.1 high mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data…
  • CVE-2026-102364 CVSS 5.3 medium mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office…
  • CVE-2026-102363 CVSS 6.3 medium mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows…
  • CVE-2026-102362 CVSS 6.9 medium mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated…
  • CVE-2026-102361 CVSS 9.3 critical mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated…