YOOtheme YOOtheme是德国YOOtheme公司的一款CMS组件。 YOOtheme 5.0.35之前版本存在跨站脚本漏洞,该漏洞源于其打包的前端框架未能阻止将某些HTML属性视为标记,允许作者角色用户进行存储型跨站脚本攻击,在查看受影响文章的任何用户浏览器中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11578 | Fluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via IDOR | |
| CVE-2026-11965 | User Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass | |
| CVE-2026-11781 | Adminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global Search AJAX |
No comments yet