浏览 23+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-27045 | WordPress WooCommerce Infinite Scroll plugin <= 1.6.2 - PHP Object Injection vulnerability | sbthemes | WooCommerce Infinite Scroll | High | 8.8 | 2026-03-25 16:14:53 | Deep Dive |
| CVE-2025-15525 | Ajax Load More – Infinite Scroll, Lazy Load & Load More <= 7.8.1 - Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure | dcooney | Ajax Load More – Infinite Scroll, Load More, & Lazy Load | Medium | 5.3 | 2026-01-31 04:35:15 | Deep Dive |
| CVE-2026-1244 | Forms Bridge <= 4.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute | codeccoop | Forms Bridge – Infinite integrations | Medium | 6.4 | 2026-01-28 06:43:42 | Deep Dive |
| CVE-2025-5084 | Post Grid Master <= 3.4.13 - Reflected Cross-Site Scripting via argsArray['read_more_text'] | mdshuvo | Post Grid Master — Post Grids & AJAX Filters | Medium | 6.1 | 2025-07-24 09:22:15 | Deep Dive |
| CVE-2025-5488 | WP Masonry & Infinite Scroll <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | kaushik07 | WP Masonry & Infinite Scroll | Medium | 6.4 | 2025-06-26 01:44:39 | Deep Dive |
| CVE-2025-49451 | WordPress Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery plugin <= 1.0.13 - Directory Traversal Vulnerability | yannisraft | Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery | High | 7.5 | 2025-06-17 15:01:42 | Deep Dive |
| CVE-2025-4775 | WordPress Infinite Scroll – Ajax Load More <= 7.4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting | dcooney | Ajax Load More – Infinite Scroll, Load More, & Lazy Load | Medium | 6.4 | 2025-06-17 01:44:11 | Deep Dive |
| CVE-2025-5586 | WordPress Ajax Load More and Infinite Scroll <= 1.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter | tushargohel | WordPress Ajax Load More and Infinite Scroll | Medium | 6.4 | 2025-06-06 06:42:50 | Deep Dive |
| CVE-2024-11642 | Post Grid Master <= 3.4.12 - Missing Authorization to Unauthenticated Local PHP File Inclusion | mdshuvo | Post Grid Master — Post Grids & AJAX Filters | Critical | 9.8 | 2025-01-09 11:11:04 | Deep Dive |
| CVE-2024-52461 | WordPress Infinite Slider plugin <= 2.0.1 - Reflected Cross Site Scripting (XSS) vulnerability | Kinsta | Infinite Slider | High | 7.1 | 2024-12-02 13:49:05 | Deep Dive |
| CVE-2024-10040 | Infinite-Scroll <= 2.6.2 - Cross-Site Request Forgery to Plugin Settings Update | paulirish-1 | Infinite-Scroll | Medium | 5.3 | 2024-10-18 04:32:52 | Deep Dive |
| CVE-2024-8505 | WordPress Infinite Scroll - Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter | dcooney | Ajax Load More – Infinite Scroll, Load More, & Lazy Load | Medium | 6.4 | 2024-10-02 09:32:00 | Deep Dive |
| CVE-2024-5796 | Infinite <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via project_url Parameter | ravichandra | Infinite | Medium | 6.4 | 2024-06-28 06:57:46 | Deep Dive |
| CVE-2024-4711 | WordPress Infinite Scroll – Ajax Load More <= 7.1.1 - Authenticated (Contributor+) Cross-Site Scripting | dcooney | Ajax Load More – Infinite Scroll, Load More, & Lazy Load | Medium | 6.4 | 2024-06-01 02:32:48 | Deep Dive |
| CVE-2024-1790 | Ajax Load More <= 7.0.1 - Authenticated (Admin+) Directory Traversal to Arbitrary File Read | dcooney | Ajax Load More – Infinite Scroll, Load More, & Lazy Load | Medium | 4.9 | 2024-04-09 18:59:03 | Deep Dive |
| CVE-2023-50874 | WordPress Ajax Load More Plugin <= 6.1.0.1 is vulnerable to Cross Site Scripting (XSS) | Darren Cooney | WordPress Infinite Scroll – Ajax Load More | Medium | 6.5 | 2023-12-28 10:01:09 | Deep Dive |
| CVE-2023-47792 | WordPress Big File Uploads Plugin <= 2.1.1 is vulnerable to Cross Site Request Forgery (CSRF) | Infinite Uploads | Big File Uploads – Increase Maximum File Upload Size | Medium | 4.3 | 2023-11-22 18:41:25 | Deep Dive |
| CVE-2023-34033 | WordPress Ajax Pagination and Infinite Scroll plugin <= 2.0.1 - Cross Site Request Forgery (CSRF) vulnerability | craigramsay | Ajax Pagination and Infinite Scroll | Medium | 4.3 | 2023-11-09 19:31:05 | Deep Dive |
| CVE-2022-4466 | WordPress Infinite Scroll - Ajax Load More < 5.6.0.3 - Contributor+ Stored XSS | Unknown | WordPress Infinite Scroll | 中危 | - | 2023-03-13 16:03:38 | Deep Dive |
| CVE-2022-2943 | WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Authenticated (Admin+) Arbitrary File Read | dcooney | Ajax Load More – Infinite Scroll, Load More, & Lazy Load | Medium | 4.9 | 2022-09-06 17:19:02 | Deep Dive |