浏览 188+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-4090 | Inquiry cart <= 3.4.2 - Cross-Site Request Forgery via Settings Form | ravster | Inquiry cart | Medium | 6.1 | 2026-04-22 07:45:38 | Deep Dive |
| CVE-2026-6370 | WordPress Mini Ajax Cart for WooCommerce plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability | HashThemes | Mini Ajax Cart for WooCommerce | Medium | 5.9 | 2026-04-15 16:02:15 | Deep Dive |
| CVE-2023-54362 | Joomla VirtueMart Shopping-Cart 4.0.12 Reflected XSS via keyword | Virtuemart | Cart | Medium | 6.1 | 2026-04-09 20:54:52 | Deep Dive |
| CVE-2026-39564 | WordPress Sunshine Photo Cart plugin < 3.6.2 - Sensitive Data Exposure vulnerability | sunshinephotocart | Sunshine Photo Cart | - | - | 2026-04-08 08:30:19 | Deep Dive |
| CVE-2026-2838 | Whole Enquiry Cart for WooCommerce <= 1.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'woowhole_success_msg' Parameter | idealwebdesignlk | Whole Enquiry Cart for WooCommerce | Medium | 4.4 | 2026-04-08 06:43:42 | Deep Dive |
| CVE-2026-0552 | Simple Shopping Cart <= 5.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsc_display_product' Shortcode | mra13 | Simple Shopping Cart | Medium | 6.4 | 2026-04-04 07:41:59 | Deep Dive |
| CVE-2018-25206 | KomSeo Cart 1.3 SQL Injection via edit.php | Sitemakin | KomSeo Cart | High | 8.2 | 2026-03-26 11:39:53 | Deep Dive |
| CVE-2026-32526 | WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.10 - Cross Site Scripting (XSS) vulnerability | VillaTheme | Abandoned Cart Recovery for WooCommerce | 中危 | - | 2026-03-25 16:15:09 | Deep Dive |
| CVE-2019-25507 | Ashop Shopping Cart Software Lastest SQL Injection via index.php | Ashopsoftware | Ashop Shopping Cart Software | High | 8.2 | 2026-03-04 17:15:53 | Deep Dive |
| CVE-2026-3148 | SourceCodester Simple and Nice Shopping Cart Script signup.php sql injection | SourceCodester | Simple and Nice Shopping Cart Script | High | 7.3 | 2026-02-25 04:02:12 | Deep Dive |
| CVE-2019-25391 | Ashop Shopping Cart Software Lastest Latest SQL Injection via bannedcustomers.php | Ashopsoftware | Ashop Shopping Cart Software | High | 8.2 | 2026-02-22 13:43:51 | Deep Dive |
| CVE-2025-68025 | WordPress Addonify Floating Cart For WooCommerce plugin <= 1.2.17 - Broken Access Control vulnerability | Addonify | Addonify Floating Cart For WooCommerce | Medium | 6.5 | 2026-02-20 15:46:36 | Deep Dive |
| CVE-2025-67973 | WordPress Sunshine Photo Cart plugin <= 3.5.6.2 - Broken Access Control vulnerability | sunshinephotocart | Sunshine Photo Cart | Medium | 6.5 | 2026-02-20 15:46:29 | Deep Dive |
| CVE-2026-2019 | Cart All In One For WooCommerce <= 1.1.21 - Authenticated (Administrator+) Code Injection via 'sc_assign_page' Setting | villatheme | Cart All In One For WooCommerce | High | 7.2 | 2026-02-18 06:42:39 | Deep Dive |
| CVE-2026-1750 | Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access | ecwid | Ecwid by Lightspeed Ecommerce Shopping Cart | High | 8.8 | 2026-02-15 03:24:34 | Deep Dive |
| CVE-2026-23796 | Session Fixation in Quick.Cart | OpenSolution | Quick.Cart | - | - | 2026-02-05 11:08:00 | Deep Dive |
| CVE-2026-23797 | Plaintext password display in Quick.Cart | OpenSolution | Quick.Cart | - | - | 2026-02-05 11:07:55 | Deep Dive |
| CVE-2026-24994 | WordPress Sunshine Photo Cart plugin <= 3.5.7.2 - Broken Access Control vulnerability | sunshinephotocart | Sunshine Photo Cart | - | - | 2026-02-03 14:08:37 | Deep Dive |
| CVE-2021-47856 | Easy Cart Shopping Cart 2021 Cross-Site Scripting via Search Parameter | NetArt Media | Easy Cart Shopping Cart | Medium | 6.4 | 2026-02-01 12:15:46 | Deep Dive |
| CVE-2026-24613 | WordPress Ecwid Shopping Cart plugin <= 7.0.6 - Broken Access Control vulnerability | Ecwid by Lightspeed Ecommerce Shopping Cart | Ecwid Shopping Cart | Medium | 5.3 | 2026-01-23 14:29:05 | Deep Dive |