云记-渗透云记 - 专注于网络安全与技术分享-第184页
CVE-2025-2010: WordPress JobWP Plugin <= 2.3.9 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2010: WordPress JobWP Plugin <= 2.3.9 - SQL Injection

漏洞标题 CVE-2025-2010: WordPress JobWP Plugin <= 2.3.9 - SQL Injection 漏洞描述 The JobWP - Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is v...
CVE-2025-24514: Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-url` Annotation-渗透云记 - 专注于网络安全与技术分享

CVE-2025-24514: Ingress-Nginx Controller – Configuration Injection via Unsanitized `auth-url` Annotation

漏洞标题 CVE-2025-24514: Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-url` Annotation 漏洞描述 A security issue was discovered in ingress-nginx https-//...
CVE-2025-34032: Moodle LMS Jmol Plugin <= 6.1 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34032: Moodle LMS Jmol Plugin <= 6.1 - Cross-Site Scripting

漏洞标题 CVE-2025-34032: Moodle LMS Jmol Plugin <= 6.1 - Cross-Site Scripting 漏洞描述 A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin ...
CVE-2025-3605: WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation-渗透云记 - 专注于网络安全与技术分享

CVE-2025-3605: WordPress Frontend Login and Registration Blocks Plugin 1.0.7 – Privilege Escalation

漏洞标题 CVE-2025-3605: WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation 漏洞描述 Privilege escalation vulnerability exists in the Frontend Logi...
CVE-2025-4380: Ads Pro Plugin <= 4.89 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4380: Ads Pro Plugin <= 4.89 - Local File Inclusion

漏洞标题 CVE-2025-4380: Ads Pro Plugin <= 4.89 - Local File Inclusion 漏洞描述 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerabl...
CVE-2025-47646: PSW Front-end Login & Registration 1.13 - Weak Password Recovery-渗透云记 - 专注于网络安全与技术分享

CVE-2025-47646: PSW Front-end Login & Registration 1.13 – Weak Password Recovery

漏洞标题 CVE-2025-47646: PSW Front-end Login & Registration 1.13 - Weak Password Recovery 漏洞描述 PSW Front-end Login & Registration plugin for WordPress contains a weak p...
CVE-2025-48954: Discourse OAuth Social Login - Cross-site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2025-48954: Discourse OAuth Social Login – Cross-site Scripting

漏洞标题 CVE-2025-48954: Discourse OAuth Social Login - Cross-site Scripting 漏洞描述 Discourse versions prior to 3.5.0.beta6 contain a stored Cross-Site Scripting (XSS) vulnerabil...
CVE-2025-49029: WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-49029: WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution

漏洞标题 CVE-2025-49029: WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution 漏洞描述 Improper Control of Generation of Code ('Code Injection&...
CVE-2025-5287: Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-5287: Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection

漏洞标题 CVE-2025-5287: Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection 漏洞描述 The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injec...
CVE-2025-53624: Docusaurus Gists Plugin < 4.0.0 - GitHub Personal Access Token Exposure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-53624: Docusaurus Gists Plugin < 4.0.0 - GitHub Personal Access Token Exposure

漏洞标题 CVE-2025-53624: Docusaurus Gists Plugin < 4.0.0 - GitHub Personal Access Token Exposure 漏洞描述 The Docusaurus gists plugin adds a page to your Docusaurus instance, di...
(CVE-2025-5961) WPvivid备份与迁移插件任意文件上传漏洞-渗透云记 - 专注于网络安全与技术分享

(CVE-2025-5961) WPvivid备份与迁移插件任意文件上传漏洞

漏洞标题 (CVE-2025-5961) WPvivid备份与迁移插件任意文件上传漏洞 漏洞描述 (CVE-2025-5961) WPvivid备份与迁移插件任意文件上传漏洞 PoC代码 暂无
CVE-2018-17207: WordPress Duplicator Plugin < 1.2.42 - Arbitrary Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2018-17207: WordPress Duplicator Plugin < 1.2.42 - Arbitrary Code Execution

漏洞标题 CVE-2018-17207: WordPress Duplicator Plugin < 1.2.42 - Arbitrary Code Execution 漏洞描述 An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing le...
CVE-2019-9881: WPEngine WPGraphQL 0.2.3 - Unauthenticated Comment Posting-渗透云记 - 专注于网络安全与技术分享

CVE-2019-9881: WPEngine WPGraphQL 0.2.3 – Unauthenticated Comment Posting

漏洞标题 CVE-2019-9881: WPEngine WPGraphQL 0.2.3 - Unauthenticated Comment Posting 漏洞描述 The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenti...
CVE-2020-27615: WordPress Loginizer < 1.6.4 – Unauthenticated SQL Injection via `log` Parameter-渗透云记 - 专注于网络安全与技术分享

CVE-2020-27615: WordPress Loginizer < 1.6.4 – Unauthenticated SQL Injection via `log` Parameter

漏洞标题 CVE-2020-27615: WordPress Loginizer < 1.6.4 – Unauthenticated SQL Injection via `log` Parameter 漏洞描述 The Loginizer plugin before 1.6.4 for WordPress allows SQL inj...
CVE-2024-2771: Contact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege Escalation-渗透云记 - 专注于网络安全与技术分享

CVE-2024-2771: Contact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege Escalation

漏洞标题 CVE-2024-2771: Contact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege Escalation 漏洞描述 The plugin is vulnerable to privilege escalation due...
CVE-2024-8353: GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-8353: GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object Injection

漏洞标题 CVE-2024-8353: GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object Injection 漏洞描述 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPr...