Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

漏洞数据库 - AI 增强中文 CVE 平台 与情报

浏览 32+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。

Found 32 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-3017 Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection shapedpluginSmart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts High 7.2 2026-04-14 05:30:33 Deep Dive
CVE-2025-8481 Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid <= 1.1.7 - Cross-Site Request Forgery mdimran41Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid Medium 4.3 2025-09-11 07:24:58 Deep Dive
CVE-2024-9645 Post Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSS UnknownPost Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry--2025-05-15 20:07:22 Deep Dive
CVE-2025-24782 WordPress Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion vulnerability wpWaxPost Grid, Slider & Carousel Ultimate Medium 6.5 2025-01-27 14:22:20 Deep Dive
CVE-2024-13408 Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion wpwaxPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget High 7.5 2025-01-24 11:07:33 Deep Dive
CVE-2024-13409 Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() wpwaxPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget High 7.5 2025-01-24 11:07:31 Deep Dive
CVE-2024-10536 FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 6.0.0 - Missing Authorization to Authenticated (Subscriber+) Shortcode Export wpqodeFancyPost – Post Blocks, Grids & Sliders for Block Editor and Elementor Medium 4.3 2025-01-07 05:24:09 Deep Dive
CVE-2024-5020 Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library extendthemesColibri Page Builder Medium 6.4 2024-12-04 08:22:47 Deep Dive
CVE-2022-4974 Freemius SDK <= 2.4.2 - Missing Authorization Checks dashlabsltdYASR – Yet Another Star Rating Plugin for WordPress Medium 6.3 2024-10-16 06:43:30 Deep Dive
CVE-2024-38686 WordPress FancyPost plugin <= 5.3.1 - Cross Site Scripting (XSS) vulnerability PluginicFancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Medium 6.5 2024-07-20 07:40:06 Deep Dive
CVE-2024-5662 Ultimate Post Kit Addons For Elementor – (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) <= 3.11.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Count (Static) Widget bdthemesUltimate Post Kit Addons for Elementor Medium 6.4 2024-06-28 08:33:29 Deep Dive
CVE-2024-3020 Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection shapedpluginCarousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel High 7.2 2024-04-10 04:30:22 Deep Dive
CVE-2024-2949 Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode' shapedpluginCarousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Medium 6.4 2024-04-06 06:47:19 Deep Dive
CVE-2024-29925 WordPress Post Grid, Slider & Carousel Ultimate plugin <= 1.6.6 - Cross Site Scripting (XSS) vulnerability wpWaxPost Grid, Slider & Carousel Ultimate Medium 6.5 2024-03-27 07:26:10 Deep Dive
CVE-2024-2006 Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 - Authenticated (Contributor+) PHP Object Injection in outpost_shortcode_metabox_markup wpwaxPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget High 8.8 2024-03-13 15:27:04 Deep Dive
CVE-2024-0612 Content Views <= 3.6.2 - Authenticated(Administrator+) Stored Cross-Site Scripting via settings pt-guyContent Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor) Medium 4.4 2024-02-05 21:21:57 Deep Dive
CVE-2023-5815 News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion infornwebBlog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News High 8.1 2023-11-22 15:33:22 Deep Dive
CVE-2022-4747 Post Category Image With Grid and Slider < 1.4.8 - Contributor+ Stored XSS via Shortcode UnknownPost Category Image With Grid and Slider 中危 -2023-02-06 19:59:31 Deep Dive
CVE-2022-4707 Royal Elementor Addons <= 1.3.59 - Cross-Site Request Forgery to Menu Template creation wproyalRoyal Addons for Elementor – Addons and Templates Kit for Elementor Medium 4.3 2023-01-10 16:55:52 Deep Dive
CVE-2022-4701 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Activation wproyalRoyal Addons for Elementor – Addons and Templates Kit for Elementor Medium 4.3 2023-01-10 16:55:47 Deep Dive