Exrick records
10 published records for vendor exrick.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-24112Proof of concept | xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.exrick · xmall · CWE-89 | Critical9.8 | — | 3.3% | Feb 5, 2024 |
39Monitor | CVE-2025-28399No exploit | An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controlexrick · xmall · CWE-269 | Critical9.8 | — | 0.6% | Apr 15, 2025 |
39Monitor | CVE-2025-45612No exploit | Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.exrick · xmall · CWE-284 | Critical9.8 | — | 0.5% | May 5, 2025 |
32Monitor | CVE-2023-36331No exploit | Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via maexrick · xmall · CWE-639 | High8.2 | — | 0.2% | Jan 12, 2026 |
24Monitor | CVE-2021-43432No exploit | A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.exrick · xmall · CWE-79 | Medium6.1 | — | 0.8% | Apr 7, 2022 |
24Monitor | CVE-2025-65540No exploit | Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data.exrick · xmall · CWE-79 | Medium6.1 | — | 0.2% | Nov 29, 2025 |
22Monitor | CVE-2025-8525No exploit | Exrick xboot Spring Boot Admin/Spring Actuator information disclosureexrick · xboot · CWE-200 | Medium5.5 | — | 0.4% | Aug 4, 2025 |
11Monitor | CVE-2025-8528No exploit | Exrick xboot getMenuList sensitive information in a cookieexrick · xboot · CWE-312 | Low2.9 | — | 0.3% | Aug 4, 2025 |
8Monitor | CVE-2025-8526No exploit | Exrick xboot UploadController.java upload unrestricted uploadexrick · xboot · CWE-284 | Low2.1 | — | 0.3% | Aug 4, 2025 |
8Monitor | CVE-2025-8527No exploit | Exrick xboot Swagger SecurityController.java server-side request forgeryexrick · xboot · CWE-918 | Low2.1 | — | 0.3% | Aug 4, 2025 |
- CVE-2024-2411240Plan
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
CriticalCVSS 9.8Proof of conceptEPSS 3%exrick · xmallFeb 5, 2024
- CVE-2025-2839939Monitor
An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Control
CriticalCVSS 9.8No exploitEPSS 1%exrick · xmallApr 15, 2025
- CVE-2025-4561239Monitor
Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.
CriticalCVSS 9.8No exploitEPSS 1%exrick · xmallMay 5, 2025
- CVE-2023-3633132Monitor
Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via ma
HighCVSS 8.2No exploitEPSS 0%exrick · xmallJan 12, 2026
- CVE-2021-4343224Monitor
A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.
MediumCVSS 6.1No exploitEPSS 1%exrick · xmallApr 7, 2022
- CVE-2025-6554024Monitor
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data.
MediumCVSS 6.1No exploitEPSS 0%exrick · xmallNov 29, 2025
- CVE-2025-852522Monitor
Exrick xboot Spring Boot Admin/Spring Actuator information disclosure
MediumCVSS 5.5No exploitEPSS 0%exrick · xbootAug 4, 2025
- CVE-2025-852811Monitor
Exrick xboot getMenuList sensitive information in a cookie
LowCVSS 2.9No exploitEPSS 0%exrick · xbootAug 4, 2025
- CVE-2025-85268Monitor
Exrick xboot UploadController.java upload unrestricted upload
LowCVSS 2.1No exploitEPSS 0%exrick · xbootAug 4, 2025
- CVE-2025-85278Monitor
Exrick xboot Swagger SecurityController.java server-side request forgery
LowCVSS 2.1No exploitEPSS 0%exrick · xbootAug 4, 2025