在 FluentCMS 0.0.5 及更早版本中发现一个漏洞。该漏洞影响文件 中的 函数。通过特定操作可能导致授权检查缺失(即访问控制失效)。攻击者可以从远程发起攻击。利用该漏洞的方法已公开,因此可能被实际利用。项目方已通过问题报告提前获知此问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | FluentCMS | 0.0.1 |
cpe:2.3:a:fluentcms:fluentcms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86289 | 4.3 MEDIUM | Ollama GGUF Decoder gguf.go readGGUFV1String integer overflow |
| CVE-2026-86285 | 4.3 MEDIUM | BookStack Attachment Edit Endpoint AttachmentController.php getUpdateForm access control |
| CVE-2026-86244 | 4.3 MEDIUM | FastAdmin User Controller User.php login cross site scripting |
No comments yet