Magento 2 的 Magefan Blog GraphQL(magefan/module-blog-graph-ql)中 GraphQL 查询存在信息泄露漏洞,受影响版本为 2.2.1 及更早版本。远程未认证的攻击者可通过向 端点发送 POST 请求,获取博客评论者的电子邮件地址以及内部客户和管理员的标识符。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39020 | 5.5 MEDIUM | Wings3D 2.4.1 恶意OBJ文件致拒绝服务 |
| CVE-2026-52482 | SJRC F11固件(2019-09-17)远程信息泄露漏洞 | |
| CVE-2025-51619 | Thesycon DPC 1.4.0 驱动内存越界致系统崩溃 | |
| CVE-2026-38998 | LIVE555 2026.02.26 释放后使用致DoS | |
| CVE-2026-79322 | Mageplaza Blog 4.3.2 存在SQL注入 | |
| CVE-2026-79324 | Mageplaza GDPR 4.2.9 缺失授权 | |
| CVE-2026-71613 | GPAC特定版本j2kdec_process堆溢出漏洞 | |
| CVE-2026-71612 | GPAC指定版本nhntdmx_process缓冲区溢出 | |
| CVE-2026-71614 | GPAC c2dee3a 远程代码执行漏洞 | |
| CVE-2026-71616 | GPAC 指定提交前存在拒绝服务漏洞 |
No comments yet