Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2026-4907
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Page-Replica Page Replica Endpoint sitemap sitemap.fetch server-side request forgery
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted element is the function sitemap.fetch of the file /sitemap of the component Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
服务端请求伪造(SSRF)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Page Replica 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Page Replica是Page Replica开源的一个网页内容提取与结构化处理工具。 Page Replica e4a7f52e75093ee318b4d5a9a9db6751050d2ad0及之前版本存在代码问题漏洞,该漏洞源于对文件/sitemap中参数url的操作不当,可能导致服务端请求伪造。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Page-ReplicaPage Replica e4a7f52e75093ee318b4d5a9a9db6751050d2ad0 -
II. Public POCs for CVE-2026-4907
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2026-4907
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2026-4907

No comments yet


Leave a comment