References https://nvd.nist.gov/vuln/detail/CVE-2025-8191 https://avd.aliyun.com/detail?id=AVD-2025-8191 https://github.com/advisories/GHSA-cw4g-wcrm-x4x7 https://cve.imfht.com/detail/CVE-2025-8191 https://access.redhat.com/security/cve/cve-2025-8191 https://www.tenable.com/cve/CVE-2025-8191 https://www.cve.org/CVERecord?id=CVE-2025-8191 https://github.com/zast-ai/vulnerability-reports/blob/main/mall/DOM_XSS.md https://vuldb.com/?id.317604
Related VulnerabilitiesXMall /item/list SQL 注入漏洞(CVE-2024-24112)DSMall /index.php 代码执行漏洞(CVE-2025-8764)linlinjava litemall任意文件上传漏洞(CVE-2025-8753) Linlinjava Litemall 文件删除功能路径遍历漏洞(CVE-2025-8755)macrozheng mall UmsMemberController订单ID参数授权绕过漏洞PoCCVE-2019-1653: Cisco Small Business WAN VPN Routers - Sensitive Information DisclosurePoCCVE-2019-1943: Cisco Small Business 200,300 and 500 Series Switches - Open RedirectPoCCVE-2021-1472: Cisco Small Business RV Series - OS Command InjectionPoCCVE-2024-24112: Exrick XMall - SQL InjectionPoCCVE-2024-24112: Exrick XMall 开源商城 SQL注入漏洞XMall商城listSearch存在SQL注入漏洞DSMall 开源多用户商城系统存在远程文件包含漏洞DSMall 移动商城网店系统 cart参数 反序列化代码执行漏洞