在 PbootCMS 3.2.22 及更早版本中已发现一个安全漏洞。该漏洞位于组件 Template Rendering(模板渲染)的文件 中的 函数。通过对参数 的不当处理,导致跨站脚本攻击(XSS)成为可能。攻击者可远程实施此攻击。利用代码已公开,可被用于发起攻击。相关 GitHub 问题报告已以“已完成”(completed)为原因被关闭。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | PbootCMS | 3.2.0 |
cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92399 | 7.3 HIGH | GPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflow |
| CVE-2026-92380 | 7.3 HIGH | WuzhiCMS Remote Image Fetch index.php saveRemote server-side request forgery |
| CVE-2026-92416 | 4.3 MEDIUM | Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request asse |
| CVE-2026-92383 | 4.3 MEDIUM | PbootCMS User Management UserController.php mod cross-site request forgery |
| CVE-2026-51990 | CVE-2026-51990 |
No comments yet