PatchSiren

gz-yami CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM gz-yami CVE published 2026-10-11

CVE-2026-108691

CVE-2026-108691 is a vulnerability in mall4j through version 4.0 that allows authenticated storefront customers to delete other shoppers' cart items due to an improper authorization issue. This is caused by an operator precedence error in the cleanExpiryProdList SQL statement. An attacker can exploit this by sending a single DELETE request to /p/shopCart/cleanExpiryProdList, which can remove every user's [truncated]