浏览 89+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-1540 | Spam Protect for Contact Form 7 < 1.2.10 - Editor+ Remote Code Execution | Unknown | Spam Protect for Contact Form 7 | - | - | 2026-04-02 06:00:10 | Deep Dive |
| CVE-2026-32544 | WordPress OOPSpam Anti-Spam plugin <= 1.2.62 - Cross Site Scripting (XSS) vulnerability | OOPSpam Team | OOPSpam Anti-Spam | 中危 | - | 2026-03-25 16:15:12 | Deep Dive |
| CVE-2026-32496 | WordPress Spam Protect for Contact Form 7 plugin <= 1.2.9 - Arbitrary File Deletion vulnerability | NYSL | Spam Protect for Contact Form 7 | 中危 | - | 2026-03-25 16:15:00 | Deep Dive |
| CVE-2026-3213 | Anti-Spam by CleanTalk - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-014 | Drupal | Anti-Spam by CleanTalk | 中危 | - | 2026-03-25 15:22:27 | Deep Dive |
| CVE-2026-3353 | Comment SPAM Wiper <= 1.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'API Key' Setting | intermod | Comment SPAM Wiper | Medium | 4.4 | 2026-03-21 03:27:04 | Deep Dive |
| CVE-2026-2112 | Dam Spam <= 1.0.8 - Cross-Site Request Forgery to Arbitrary Pending Comment Deletion | webguyio | Dam Spam | Medium | 4.3 | 2026-02-18 07:25:42 | Deep Dive |
| CVE-2026-1490 | Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation | cleantalk | Spam protection, Honeypot, Anti-Spam by CleanTalk | Critical | 9.8 | 2026-02-15 02:22:57 | Deep Dive |
| CVE-2025-62735 | WordPress User Spam Remover plugin <= 1.1 - Sensitive Data Exposure vulnerability | Joel | User Spam Remover | - | - | 2025-12-09 14:52:22 | Deep Dive |
| CVE-2025-12406 | Project Honey Pot Spam Trap <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting | awensley | Project Honey Pot Spam Trap | Medium | 6.1 | 2025-11-18 08:27:37 | Deep Dive |
| CVE-2025-12094 | OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) <= 1.2.53 - Unauthenticated IP Header Spoofing | oopspam | OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) | Medium | 5.3 | 2025-10-31 08:25:55 | Deep Dive |
| CVE-2025-57935 | WordPress Bot Block – Stop Spam Referrals in Google Analytics Plugin <= 2.6 - Cross Site Scripting (XSS) Vulnerability | Ricky Dawn | Bot Block – Stop Spam Referrals in Google Analytics | Medium | 5.9 | 2025-09-22 18:25:03 | Deep Dive |
| CVE-2025-58270 | WordPress NIX Anti-Spam Light Plugin <= 0.0.4 - Cross Site Request Forgery (CSRF) Vulnerability | NIX Solutions Ltd | NIX Anti-Spam Light | High | 7.1 | 2025-09-22 18:23:15 | Deep Dive |
| CVE-2025-9888 | Maspik <= 2.5.6 - Cross-Site Request Forgery | yonifre | Maspik – Ultimate Spam Protection | Medium | 4.3 | 2025-09-10 06:38:50 | Deep Dive |
| CVE-2025-9979 | Maspik <= 2.5.6 - Authenticated (Subscriber+) Missing Authorization to Spam Log Export | yonifre | Maspik – Ultimate Spam Protection | Medium | 4.3 | 2025-09-10 06:38:47 | Deep Dive |
| CVE-2025-9376 | Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 11.58 - Insufficient Authorization to Unauthenticated Blocklist Bypass | sminozzi | Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection | Medium | 6.5 | 2025-08-28 11:16:22 | Deep Dive |
| CVE-2010-20109 | Barracuda Spam & Virus Firewall "locale" Path Traversal | Barracuda Networks | Spam & Virus Firewall | - | - | 2025-08-21 20:09:04 | Deep Dive |
| CVE-2025-6722 | BitFire <= 4.5 - Unauthenticated Information Exposure | bitslip6 | BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security | Medium | 5.3 | 2025-08-02 09:23:31 | Deep Dive |
| CVE-2025-24778 | WordPress No Spam At All plugin <= 1.3 - Broken Access Control Vulnerability | De paragon | No Spam At All | Medium | 5.4 | 2025-06-06 12:54:38 | Deep Dive |
| CVE-2025-49283 | WordPress Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant plugin <= 4.1.1 - Cross Site Request Forgery (CSRF) Vulnerability | Matthias Nordwig | Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant | Medium | 4.3 | 2025-06-06 12:53:41 | Deep Dive |
| CVE-2025-2935 | Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms <= 2024.7 - Cross-Site Request Forgery to Multiple Administrative Actions | webguyio | Stop Spammers Classic | Medium | 5.4 | 2025-06-06 06:42:53 | Deep Dive |