Cyber Resilience

CVE-2025-8991

Linlinjava Litemall ≤ 1.8.0

Public PoC
Published
15 August 2025
Modified
17 June 2026
Patch / advisory
CVSS Score v4 2.1
Click a component to see what it means
Raw vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0032 25th percentile
Risk Priority 27 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2025-8991 is a low-severity an unspecified weakness vulnerability in Linlinjava Litemall. Its CVSS base score is 2.1 (Low).

Operationally, ranked at the 25th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file /admin/config/express of the component Business Logic Handler. The manipulation of the argument litemall_express_freight_min leads to business logic errors. The…

more

attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-8965Same product: Linlinjava Litemall
CVE-2024-24323Same product: Linlinjava Litemall
CVE-2025-8764Same product: Linlinjava Litemall
CVE-2025-10291Same product: Linlinjava Litemall
CVE-2024-6452Same product: Linlinjava Litemall
CVE-2024-46382Same product: Linlinjava Litemall
CVE-2025-8974Same product: Linlinjava Litemall
CVE-2025-8753Same product: Linlinjava Litemall
CVE-2025-6702Same product: Linlinjava Litemall
CVE-2023-29294Shared CWE-840

Affected Assets

linlinjava
litemall
≤ 1.8.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References