CVEs affecting projects tracked on Release Alert, from NVD & OSV.
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.