All 5 CVE vulnerabilities found in CMB2, with AI-generated Chinese analysis, references, and POCs.
Vendor: jtsternberg
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-102772 | CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_code' Field CWE-79 | 7.2 | High | 2026-10-02 |
| CVE-2026-97336 | CMB2 <= 2.13.0 - Unauthenticated Stored Cross-Site Scripting via 'file_list' Field Type CWE-79 | 7.2 | High | 2026-10-02 |
| CVE-2026-97270 | WordPress CMB2 plugin <= 2.13.0 - Cross Site Scripting (XSS) vulnerability CWE-79 | 6.5 | Medium | 2026-09-30 |
| CVE-2026-80338 | CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler | - | - | 2026-09-24 |
| CVE-2024-1792 | CMB2 <= 2.10.1 - Authenticated (Contributor+) PHP Object Injection CWE-502 | 7.5 | High | 2024-04-09 |
All 5 known CVE vulnerabilities affecting CMB2 with full Chinese analysis, references, and POCs where available.