newbee-mall · Issues· 28 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #127
Negative Cart Quantity Offsets the Order Total and Inflates the Stock Counter
Updated Sep 16, 2026 - #126
[Sercuity]新蜂商城(newbee-mall)后台文件上传无后缀白名单,结合图片/HTML多型文件绕过BufferedImage校验,导致存储型XSS。
Updated Aug 26, 2026 - #125
[Security]新蜂商城(newbee-mall)POST /admin/profile/name 缺乏 CSRF 防护,可跨站强制重命名管理员登录用户名,导致管理员被永久锁定
Updated Aug 26, 2026 - #124
[Security]新蜂商城(newbee-mall) GET /admin/logout 接口缺少 CSRF 防护,可被诱导触发强制登出。
Updated Aug 26, 2026 - #120
[Security] Unauthenticated Order Payment Status Manipulation via /paySuccess
Updated Jul 20, 2026 - #122
[Security] Stored XSS in Rich Text Content on the Traditional Product Detail Page
Updated Jul 5, 2026 - #121
[Security] Stored XSS in Product Detail Rich Text Content
Updated Jul 5, 2026 - #117
Logical Vulnerability
Updated May 14, 2026 - #119
Default admin credentials + weak MD5 password hashing enable full admin compromise and credential cracking
Updated Feb 12, 2026 - #118
Experimenting with a.i.
Updated Feb 11, 2026 - #116
File Upload Vulnerability
Updated Feb 10, 2026 - #115
CSRF Vulnerability in Admin Carousel Management
Updated Feb 5, 2026 - #114
CSRF Vulnerability in Personal Information Update
Updated Feb 5, 2026 - #113
CSRF Vulnerability in Payment Processing
Updated Feb 5, 2026 - #112
CSRF Vulnerability in Shopping Cart Item Deletion
Updated Feb 5, 2026