Weak Password Hashing in Newbee Mall by Newbee Ltd
CVE-2026-26219
9.3CRITICAL
What is CVE-2026-26219?
Newbee Mall employs an unsalted MD5 hashing algorithm for storing and verifying user passwords. This approach lacks individual salts and computational cost controls, making it susceptible to offline attacks. If password hashes are accessed through database breaches or backup leaks, attackers can swiftly recover plaintext credentials, posing significant risks to user security.
Affected Version(s)
newbee-mall 1.0.0
