CVE-2026-102362: Gz-Yami MALL4J
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by supplying the prodCommId parameter without authorization checks.
Affected products
- Gz-Yami MALL4J: up to and including 4.0
Published 2026-09-29. Last modified 2026-09-30.