4.5.13 版本之前的 Groundhogg — CRM, 新闻通讯及营销自动化 WordPress 插件,在未对提交到某些可选网页表单字段中的值进行验证或转义的情况下,便将其存储并在管理区域中输出,这使得未认证的用户能够对高权限用户发起存储型跨站脚本(Stored XSS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Groundhogg — CRM, Newsletters, and Marketing Automation | 0 ~ 4.5.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81766 | Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation vi | |
| CVE-2026-78364 | MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List | |
| CVE-2026-19722 | WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup | |
| CVE-2026-76585 | Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Para | |
| CVE-2026-14835 | SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Pos | |
| CVE-2026-14307 | Geotargeting WP < 3.5.6.2 - Reflected XSS |
No comments yet