cloudways Breeze Cache是cloudways的消息队列中间件。 WordPress Breeze Cache 2.5.6之前版本存在跨站脚本漏洞,该漏洞源于HTML压缩过程中使用可预测的替换哈希且滥用正则表达式,可能导致未经身份验证的攻击者通过预测占位符格式在最终HTML输出中注入任意HTML属性,造成存储型跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Breeze Cache | < 2.5.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Breeze Cache | 0 ~ 2.5.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12275 | Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content | |
| CVE-2026-12397 | WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR | |
| CVE-2026-12582 | Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id | |
| CVE-2026-12396 | WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rejection | |
| CVE-2026-11964 | User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verifica | |
| CVE-2026-12081 | Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object | |
| CVE-2026-12273 | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation | |
| CVE-2026-12271 | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR | |
| CVE-2026-12274 | Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR | |
| CVE-2026-11963 | User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier M |
No comments yet