smub 厂商相关 96 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。
smub 主要涉及软件供应链安全领域,旨在识别和缓解开源组件风险。其收录的 75 条 CVE 多集中于远程代码执行、跨站脚本及权限绕过等高危类型,反映出组件在输入验证与访问控制方面的普遍缺陷。值得关注的是,该项目通过持续追踪漏洞数据,为开发者提供了关键的风险预警机制,有助于在集成第三方库前评估潜在威胁,提升整体系统的安全性。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-84909 | Custom Twitter Feeds 存储型跨站脚本漏洞 — Custom Twitter Feeds – A Tweets Widget or X Feed Widget CWE-79 | 6.4 | Medium | 2026-09-18 |
| CVE-2026-77189 | WordPress Charitable SQL注入漏洞 — Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) CWE-89 | 6.5 | Medium | 2026-09-01 |
| CVE-2026-3423 | smub Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More 跨站脚本漏洞 — Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More CWE-79 | 6.4 | Medium | 2026-08-28 |
| CVE-2026-16775 | WordPress Smash Balloon Social Post Feed 跨站脚本漏洞 — Smash Balloon Social Post Feed – Simple Social Feeds for WordPress CWE-79 | 6.4 | Medium | 2026-08-16 |
| CVE-2026-15452 | WordPress Smash Balloon Social Photo Feed 跨站脚本漏洞 — Smash Balloon Social Photo Feed – Easy Social Feeds Plugin CWE-79 | 4.7 | Medium | 2026-08-05 |
| CVE-2026-12476 | WordPress Easy Digital Downloads 任意文件上传漏洞 — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy CWE-434 | 7.2 | High | 2026-07-29 |
| CVE-2026-15782 | WordPress WPForms 跨站脚本漏洞 — WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More CWE-79 | 4.9 | Medium | 2026-07-21 |
| CVE-2026-12002 | WordPress Smash Balloon Social Photo Feed 跨站请求伪造漏洞 — Smash Balloon Social Photo Feed – Easy Social Feeds Plugin CWE-352 | 4.7 | Medium | 2026-07-08 |
| CVE-2026-12127 | Syed Balkhi WPForms 输入验证错误漏洞 — WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More CWE-93 | 5.3 | Medium | 2026-07-01 |
| CVE-2026-8613 | WordPress plugin aThemes Addons for Elementor 跨站脚本漏洞 — aThemes Addons for Elementor CWE-79 | 6.4 | Medium | 2026-06-10 |
| CVE-2026-7792 | WordPress plugin WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More 数据伪造问题漏洞 — WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More CWE-345 | 5.3 | Medium | 2026-06-06 |
| CVE-2026-10038 | WordPress plugin Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More 安全漏洞 — Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More CWE-639 | 4.3 | Medium | 2026-06-05 |
| CVE-2026-7526 | WordPress plugin PDF Embedder 信息泄露漏洞 — PDF Embedder – PDF Viewer & Embed PDF Files for WordPress CWE-200 | 4.3 | Medium | 2026-05-28 |
| CVE-2026-7533 | WordPress plugin Easy Digital Downloads 跨站请求伪造漏洞 — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy CWE-352 | 4.3 | Medium | 2026-05-28 |
| CVE-2026-8832 | WordPress plugin WPCode 代码注入漏洞 — WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager CWE-94 | 8.8 | High | 2026-05-27 |
| CVE-2026-7636 | WordPress plugin Slider by Soliloquy 信息泄露漏洞 — Slider by Soliloquy – Responsive Image Slider for WordPress CWE-200 | 4.3 | Medium | 2026-05-22 |
| CVE-2026-6566 | WordPress plugin NextGEN Gallery 安全漏洞 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery CWE-639 | 4.3 | Medium | 2026-05-20 |
| CVE-2026-5075 | WordPress plugin All in One SEO 信息泄露漏洞 — All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic CWE-200 | 4.3 | Medium | 2026-05-20 |
| CVE-2026-5361 | WordPress plugin Envira Gallery Lite 跨站脚本漏洞 — Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More CWE-79 | 6.4 | Medium | 2026-05-14 |
| CVE-2026-6177 | WordPress plugin Custom Twitter Feeds 跨站脚本漏洞 — Custom Twitter Feeds – A Tweets Widget or X Feed Widget CWE-79 | 7.2 | High | 2026-05-13 |
| CVE-2026-7619 | WordPress plugin Charitable SQL注入漏洞 — Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More CWE-89 | 6.5 | Medium | 2026-05-13 |
| CVE-2026-5488 | WordPress plugin ExactMetrics 安全漏洞 — ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) CWE-862 | 5.3 | Medium | 2026-04-24 |
| CVE-2026-5464 | WordPress plugin ExactMetrics 安全漏洞 — ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) CWE-862 | 7.2 | High | 2026-04-23 |
| CVE-2026-3177 | WordPress plugin Charitable 数据伪造问题漏洞 — Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More CWE-345 | 5.3 | Medium | 2026-04-07 |
| CVE-2026-1463 | WordPress plugin NextGEN Gallery 安全漏洞 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery CWE-98 | 8.8 | High | 2026-03-18 |
| CVE-2026-1992 | WordPress plugin ExactMetrics – Google Analytics Dashboard for WordPress 安全漏洞 — ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) CWE-639 | 8.8 | High | 2026-03-11 |
| CVE-2026-1993 | WordPress plugin ExactMetrics – Google Analytics Dashboard for WordPress 安全漏洞 — ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) CWE-269 | 8.8 | High | 2026-03-11 |
| CVE-2026-1236 | WordPress plugin Envira Gallery 跨站脚本漏洞 — Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More CWE-79 | 6.4 | Medium | 2026-03-04 |
| CVE-2026-2471 | WordPress plugin WP Mail Logging 代码问题漏洞 — WP Mail Logging CWE-502 | 7.5 | High | 2026-02-28 |
| CVE-2025-14384 | WordPress plugin All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic 安全漏洞 — All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic CWE-862 | 4.3 | Medium | 2026-01-16 |
本页汇总了 smub 厂商截至目前公开的全部 96 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。