目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

漏洞列表 - 第 19

漏洞ID 标题 厂商 产品 风险等级 CVSS 评分 发布日期 AI 分析
CVE-2026-92975 Groundhogg <=4.8.3 未授权权限提升致身份混淆漏洞 trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation 高危 8.1 2026-10-10 05:31:03 深度分析
CVE-2026-104899 GeoDirectory <= 2.8.187 未授权本地文件包含漏洞 paoltaia GeoDirectory – WP Business Directory Plugin and Classified Listings Directory 高危 8.1 2026-10-10 05:31:03 深度分析
CVE-2026-77183 FooSales <=1.43.0 权限提升漏洞 foosales FooSales – Point of Sale (POS) for WooCommerce 高危 8.8 2026-10-10 05:31:02 深度分析
CVE-2026-18558 Embed Any Document <= 2.7.13 存储型XSS漏洞 awsmin Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files 中危 6.4 2026-10-10 05:31:02 深度分析
CVE-2026-91862 Getwid <= 3.0.1 通过 'data-image-points' 存储型 XSS 漏洞 jetmonsters Getwid – Gutenberg Blocks 中危 6.4 2026-10-10 05:31:02 深度分析
CVE-2026-94421 Church Admin <= 5.1.2 邮件参数存储型XSS漏洞 andy_moyle Church Admin 中危 6.4 2026-10-10 05:31:01 深度分析
CVE-2026-96667 Real Estate Manager 7.3 通过 first_name 参数存储型跨站脚本漏洞 rameez_iqbal Real Estate Manager – Property Listing and Agent Management 高危 7.2 2026-10-10 05:31:01 深度分析
CVE-2026-94375 WooCommerce Order Export 2.7.8 未授权敏感文件泄露漏洞 webtoffee Order Export & Order Import for WooCommerce 中危 5.3 2026-10-10 05:31:00 深度分析
CVE-2026-103520 HivePress ≤1.7.31 存储型跨站脚本漏洞 hivepress HivePress – Business Directory, Listings & Classified Ads Plugin 中危 6.4 2026-10-10 05:31:00 深度分析
CVE-2026-104763 Post Export Import with Media 1.17.1 路径遍历致任意文件读取漏洞 wpazleen Post Export Import with Media 中危 4.9 2026-10-10 05:31:00 深度分析
CVE-2026-14379 GamiPress 7.9.4及以下版本 存储型跨站脚本漏洞 rubengc GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI 中危 6.4 2026-10-10 05:30:59 深度分析
CVE-2026-104725 Groundhogg <=4.9 认证用户权限提升漏洞 trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation 高危 8.8 2026-10-10 05:30:59 深度分析
CVE-2026-83526 FV Player 8.0-8.1.7 任意文件上传漏洞 foliovision FV Player 8 高危 8.8 2026-10-10 05:30:58 深度分析
CVE-2026-16776 MP3 Audio Player <=5.14.2 存储型XSS漏洞 sonaar MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 中危 6.4 2026-10-10 05:30:58 深度分析
CVE-2026-104742 AI Puffer <=2.4.89 认证用户可修改语义搜索设置漏洞 senols AI Puffer – AI Chatbot, AI Writer & Automation 低危 3.1 2026-10-10 05:30:58 深度分析
CVE-2026-104741 AI Puffer <= 2.4.89 授权缺失导致未授权修改全局插件设置 senols AI Puffer – AI Chatbot, AI Writer & Automation 低危 3.1 2026-10-10 05:30:57 深度分析
CVE-2026-104766 Appointment Booking 插件 5.7.3 权限提升漏洞 latepoint Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress 高危 8.8 2026-10-10 05:30:57 深度分析
CVE-2026-78068 Table Field Add-on for ACF/SCF <=1.3.35 存储型XSS漏洞 jonua Table Field Add-on for ACF and SCF 中危 6.4 2026-10-10 05:30:57 深度分析
CVE-2026-104023 Smart Popup <=1.13.2 SQL注入漏洞 supsysticcom Smart Popup by Supsystic 中危 4.9 2026-10-10 05:30:56 深度分析
CVE-2026-18496 Booking Calendar <= 11.4.3 AJAX 敏感信息泄露漏洞 wpdevelop Booking Calendar 中危 5.3 2026-10-10 05:30:56 深度分析