Browse all 3 CVE security advisories affecting corvusinfo. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-6939 | CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter — CorvusPay WooCommerce Payment Gateway CWE-79 | 7.2 | High | 2026-07-11 |
| CVE-2026-9028 | CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization to Unauthenticated Arbitrary Order Cancellation via 'order_number' Parameter — CorvusPay WooCommerce Payment Gateway CWE-862 | 5.3 | Medium | 2026-07-09 |
| CVE-2026-9027 | CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Improper Verification of Cryptographic Signature to Payment Bypass via /wp-json/corvuspay/success/ REST Endpoint — CorvusPay WooCommerce Payment Gateway CWE-347 | 5.3 | Medium | 2026-07-09 |
This page lists every published CVE security advisory associated with corvusinfo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.