Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

trainingbusinesspros — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting trainingbusinesspros. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Trainingbusinesspros provides cybersecurity training and certification programs for professionals. Historically, their systems have been vulnerable to common classes including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. The organization has recorded 11 CVEs, with several critical flaws allowing unauthorized access and system compromise. Notable security characteristics include insufficient input validation and inadequate session management in their web-based training platforms. While no major public incidents have been widely reported, the consistent pattern of vulnerabilities suggests potential risks for organizations relying on their training infrastructure. Their CVE history reflects typical web application security challenges faced by educational technology platforms.

CVE ID Title CVSS Severity Published
CVE-2026-97644 Groundhogg <= 4.9 - Authenticated (Sales Person+) Privilege Escalation via Contact Identity Rebinding leading to Administrator Account Takeover to 'user_id' Parameter (v3 /contacts) chained with v4 /emails/test — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-269 8.8 High 2026-10-03
CVE-2026-18387 Groundhogg <= 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-89 6.5 Medium 2026-08-15
CVE-2026-11454 Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure Direct Object Reference — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-639 6.5 Medium 2026-08-05
CVE-2026-14029 Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Parameter — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-89 6.5 Medium 2026-07-02
CVE-2026-13333 Groundhogg <= 4.5.5 - Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-89 6.5 Medium 2026-06-27
CVE-2026-13331 Groundhogg <= 4.5.5 - Authenticated (Marketer+) SQL Injection via 'search' Parameter — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-89 6.5 Medium 2026-06-27
CVE-2026-13226 Groundhogg <= 4.5.4 - Authenticated (Custom+) SQL Injection via 'after' Parameter — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-89 6.5 Medium 2026-06-26
CVE-2026-4281 FormLift for Infusionsoft Web Forms <= 7.5.21 - Missing Authorization to Unauthenticated Infusionsoft Connection Hijack via OAuth Connection Flow — FormLift for Infusionsoft Web Forms CWE-862 5.3 Medium 2026-03-26
CVE-2025-12750 Groundhogg <= 4.2.6.1 - Authenticated (Admin+) SQL Injection — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-89 4.9 Medium 2025-11-21
CVE-2025-4206 WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg <= 4.1.1.2 - Authenticated (Administrator+) Arbitrary File Deletion — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-22 7.2 High 2025-05-09
CVE-2025-1267 Groundhogg <= 3.7.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via label Parameter — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-79 5.5 Medium 2025-04-01
CVE-2025-0394 Groundhogg <= 3.7.3.5 - Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Function — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-434 8.8 High 2025-01-14
CVE-2023-2717 Groundhogg <= 2.7.9.8 - Cross-Site Request Forgery to Disable All Plugins — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-352 5.4 Medium 2023-05-20
CVE-2023-2736 Groundhogg <= 2.7.9.8 - Cross-Site Request Forgery to Privilege Escalation — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-352 7.5 High 2023-05-20
CVE-2023-2735 Groundhogg <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-79 4.9 Medium 2023-05-20
CVE-2023-2716 Groundhogg <= 2.7.9.8 - Missing Authorization to Non-Arbitrary File Upload — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-862 5.4 Medium 2023-05-20
CVE-2023-2714 Groundhogg <= 2.7.9.8 - Missing Authorization to Update License — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-862 4.3 Medium 2023-05-20
CVE-2023-2715 Groundhogg <= 2.7.9.8 - Missing Authorization to Admin Account and Ticket Creation — Groundhogg — CRM, Newsletters, and Marketing Automation CWE-862 4.3 Medium 2023-05-20

This page lists every published CVE security advisory associated with trainingbusinesspros. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.