在 Brainstorm Force 的 Presto Player 插件(presto-player)中存在“网页生成时输入中和不当”(即跨站脚本攻击,XSS)漏洞,该漏洞允许存储型跨站脚本攻击(Stored XSS)。此问题影响 Presto Player 从最初版本到 4.5.2 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Brainstorm Force | Presto Player | 0 ~ 4.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102393 | 6.5 MEDIUM | WordPress Starter Templates plugin <= 4.7.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-39721 | 5.4 MEDIUM | WordPress Starter Templates plugin <= 4.7.7 - Broken Access Control vulnerability |
No comments yet