Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

漏洞数据库 - AI 增强中文 CVE 平台 与情报

浏览 621+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。

Found 621 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-22014 Oracle User Management 安全漏洞 Oracle CorporationOracle User Management Low 3.8 2026-04-21 20:35:09 Deep Dive
CVE-2026-1559 Youzify <= 1.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkin_place_id' Parameter youzifyYouzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress Medium 6.4 2026-04-18 01:26:05 Deep Dive
CVE-2026-3551 Custom New User Notification <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'User Mail Subject' Setting rafasashiCustom New User Notification Medium 4.4 2026-04-16 05:29:53 Deep Dive
CVE-2026-4949 ProfilePress <= 4.16.12 - Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription properfractionPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Medium 4.3 2026-04-15 22:26:06 Deep Dive
CVE-2026-5617 Login as User <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation via 'oclaup_original_admin' Cookie royalnavneetLogin as User – Switch User & WooCommerce Login as Customer High 8.8 2026-04-15 07:45:30 Deep Dive
CVE-2026-6203 User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter wpeverestUser Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Medium 6.1 2026-04-13 22:25:54 Deep Dive
CVE-2026-4979 UsersWP <= 1.2.58 - Authenticated (Subscriber+) Server-Side Request Forgery via 'uwp_crop' Parameter stiofansislandUsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP Medium 5.0 2026-04-11 01:25:00 Deep Dive
CVE-2025-5804 WordPress Case Theme User < 1.0.4 - Local File Inclusion Vulnerability Case ThemesCase Theme User High 7.5 2026-04-10 13:19:43 Deep Dive
CVE-2026-4977 UsersWP <= 1.2.58 - Authenticated (Subscriber+) Restricted Usermeta Modification via 'htmlvar' Parameter stiofansislandUsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP Medium 4.3 2026-04-10 01:25:01 Deep Dive
CVE-2026-5742 UsersWP <= 1.2.60 - Authenticated (Subscriber+) Stored Cross-Site Scripting via User Badge Link Substitution stiofansislandUsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP Medium 6.4 2026-04-09 03:25:58 Deep Dive
CVE-2026-1865 User Registration & Membership <= 5.1.2 - Authenticated (Subscriber+) SQL Injection via membership_ids[] wpeverestUser Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Medium 6.5 2026-04-08 11:16:57 Deep Dive
CVE-2026-39476 WordPress User Feedback plugin <= 1.10.1 - Broken Access Control vulnerability Syed BalkhiUser Feedback--2026-04-08 08:30:09 Deep Dive
CVE-2026-39475 WordPress User Feedback plugin <= 1.10.1 - SQL Injection vulnerability Syed BalkhiUser Feedback--2026-04-08 08:30:09 Deep Dive
CVE-2026-5543 PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injection PHPGurukulUser Registration & Login and User Management System Medium 6.3 2026-04-05 04:30:14 Deep Dive
CVE-2018-25250 MyBB Last User's Threads in Profile Plugin 1.2 Persistent XSS MyBBMyBB Last User's Threads in Profile Plugin High 7.2 2026-04-04 13:51:15 Deep Dive
CVE-2026-3309 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields properfractionPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Medium 6.5 2026-04-04 11:16:15 Deep Dive
CVE-2026-3445 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass properfractionPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress High 7.1 2026-04-04 08:25:20 Deep Dive
CVE-2025-15064 Ultimate Member <= 2.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via DOM Gadgets ultimatememberUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin Medium 6.4 2026-04-04 07:41:57 Deep Dive
CVE-2026-3571 Pie Register – User Registration, Profiles & Content Restriction <= 3.8.4.8 - Missing Authorization to Unauthenticated Registration Form Status Modification genetechproductsPie Register – User Registration, Profiles & Content Restriction Medium 6.5 2026-04-04 01:24:06 Deep Dive
CVE-2026-3139 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field cozmoslabsUser Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Medium 4.3 2026-03-31 11:18:56 Deep Dive