Macrozheng Mall
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Macrozheng Mall.
By the Year
In 2026 there have been 2 vulnerabilities in Macrozheng Mall with an average score of 5.5 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 5.50 |
It may take a day or so for new Mall vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Macrozheng Mall Security Vulnerabilities
macrozheng mall <=1.0.3 Remote ID Control via /returnApply/create
CVE-2026-15186
6.3 - Medium
- July 09, 2026
A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. The manipulation of the argument orderId leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor deleted the GitHub issue for this vulnerability without any explanation.
Insecure Direct Object Reference
Improper Authorization via Super Admin Password Handler in Macrozheng Mall <=1.0.3 (CVE-2026-10070)
CVE-2026-10070
4.7 - Medium
- May 29, 2026
A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of the component Super Admin Password Handler. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.
AuthZ
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Macrozheng Mall or by Macrozheng? Click the Watch button to subscribe.