CVE-2026-102363

CVE-2026-102363 published: mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carr...

View full NVD advisory → ← Back to CVE watch