stefanbohacek Fediverse Embeds是stefanbohacek个人开发者的一款嵌入Fediverse社交网络内容的脚本工具。 stefanbohacek Fediverse Embeds 1.5.8之前版本存在服务端请求伪造漏洞,该漏洞源于未验证服务器端请求的目标地址,可能导致未经身份验证的用户获取任意URL(包括内部及私有网络地址)的响应体,从而造成完全的服务器端请求伪造和开放代理。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Fediverse Embeds | < 1.5.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Fediverse Embeds | 0 ~ 1.5.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12517 | Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint | |
| CVE-2026-12270 | Everest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assistant REST Endp | |
| CVE-2026-11571 | Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV Ar | |
| CVE-2026-11875 | WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support Ticket Access | |
| CVE-2026-11869 | WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclosure via Subj |
No comments yet