Newsbee · Newbee-Mall · CVE-2026-94045
**Name of the Vulnerable Software and Affected Versions**
newbee-ltd newbee-mall versions prior to 1.0.1
**Description**
A remote cross site scripting issue exists in the Goods Save Endpoint within the `controller/common/UploadController.java` file. By manipulating the `goodsName` argument, an attacker can bypass the image-only guard because `ImageIO.read()` is format-agnostic and returns non-null for polyglot PNG payloads. Combined with the `/upload/**` static mapping, this allows the upload of a payload that results in persisted cross site scripting.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.