| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-34730 | Copier `_external_data` allows path traversal and absolute-path local file read without unsafe mode | copier-org | copier | Medium | 5.5 | 2026-04-02 18:09:16 | Deep Dive |
| CVE-2026-34726 | Copier `_subdirectory` allows template root escape via parent-directory traversal | copier-org | copier | Medium | 4.4 | 2026-04-02 18:07:36 | Deep Dive |
| CVE-2026-23986 | Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true | copier-org | copier | - | - | 2026-01-21 22:20:38 | Deep Dive |
| CVE-2026-23968 | Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false | copier-org | copier | - | - | 2026-01-21 22:13:25 | Deep Dive |
| CVE-2025-55214 | Copier safe template has filesystem write access outside destination path | copier-org | copier | - | - | 2025-08-18 16:36:47 | Deep Dive |
| CVE-2025-55201 | Copier safe template has arbitrary filesystem read/write access | copier-org | copier | - | - | 2025-08-18 16:21:26 | Deep Dive |
| CVE-2024-38673 | WordPress Multisite Content Copier/Updater plugin <= 1.5.0 - Reflected Cross Site Scripting (XSS) vulnerability | Obtain Infotech | Multisite Content Copier/Updater | High | 7.1 | 2024-07-20 07:55:24 | Deep Dive |
| CVE-2022-0503 | Multisite Content Copier/Updater < 2.1.2 - Reflected Cross-Site Scripting | Unknown | WordPress Multisite Content Copier/Updater | 中危 | - | 2022-03-14 14:41:35 | Deep Dive |
| CVE-2021-25039 | Multisite Content Copier/Updater < 2.1.0 - Reflected Cross-Site Scripting | Unknown | WordPress Multisite Content Copier/Updater | 中危 | - | 2022-03-07 08:16:16 | Deep Dive |