Web App Scanning 的 Component Vulnerability 系列

ID名称严重性
113480WP Statistics Plugin for WordPress < 12.0.6 跨站脚本
medium
113479All In One WP Security & Firewall Plugin for WordPress < 3.8.3 多个 SQL 注入
high
113478All In One WP Security & Firewall Plugin for WordPress < 3.8.8 SQL 注入
critical
113477Elementor Plugin for WordPress < 3.6.3 错误授权
high
113476WP-PostViews Plugin for WordPress < 1.63 跨站请求伪造
high
113475WP eCommerce Plugin for WordPress < 3.8.7.6 SQL 注入
critical
113474WP-Print Plugin for WordPress < 2.52 跨站请求伪造
high
113473WP Photo Album Plus Plugin for WordPress < 6.1.3 多个跨站脚本
medium
113472WP EasyCart Plugin for WordPress < 3.0.9 无限制文件上传
high
113471WP Go Maps Plugin for WordPress < 7.10.43 跨站脚本
medium
113470Auth0 Plugin for WordPress < 4.0.0 多个漏洞
high
113469WP Data Access Plugin for WordPress < 5.0.0 SQL 注入
critical
113468WP Visitor Statistics Plugin for WordPress < 5.6 SQL 注入
high
113467WP DBManager Plugin for WordPress < 2.7.2 多个漏洞
high
113466WP DBManager Plugin for WordPress < 2.80.8 代码注入
high
113465Affiliates Manager Plugin for WordPress < 2.9.14 多个漏洞
high
113464WP Maintenance Plugin for WordPress < 6.0.8 存储型跨站脚本
medium
113463WP Maintenance Plugin for WordPress < 6.0.6 存储型跨站脚本
medium
113462WP-Polls Plugin for WordPress < 2.77.0 存储型跨站脚本
low
113461Wordfence Security Plugin for WordPress < 7.6.0 存储型跨站脚本
medium
113460Yoast SEO Plugin for WordPress 1.7.x < 1.7.4 多个漏洞
critical
113459Yoast SEO Plugin for WordPress 1.6.x < 1.6.4 多个漏洞
critical
113458Yoast SEO Plugin for WordPress < 1.5.7 多个漏洞
critical
113457phpMyAdmin 4.9.x < 4.9.10 信息泄露漏洞
high
113456phpMyAdmin 5.1.x < 5.1.3 信息泄露漏洞
high
113449已启用 WordPress Cron
medium
113454lighttpd < 1.4.54 整数溢出
critical
113453lighttpd 1.4.56 < 1.4.59 拒绝服务
high
113451Lodash < 4.17.5 原型污染
medium
113450Lodash < 4.17.11 原型污染
medium
113438GLPI 9.1 < 10.0.3 SQL 注入
critical
113437GLPI 9.1 < 9.5.6 Rest API IP 限制绕过
high
113436GLPI 默认凭据
high
113435GLPI < 9.3.4 SQL 注入
critical
113447Atlassian Crowd 5.0.x < 5.0.3 错误配置
critical
113446Atlassian Bitbucket 8.4.x < 8.4.2 命令注入
critical
113445Atlassian Bitbucket 8.3.x < 8.3.3 命令注入
critical
113444Atlassian Bitbucket 8.2.x < 8.2.4 命令注入
critical
113443Atlassian Bitbucket 8.1.x < 8.1.5 命令注入
critical
113442Atlassian Bitbucket 8.0.x < 8.0.5 命令注入
critical
113441Atlassian Bitbucket 7.18.x < 7.21.6 命令注入
critical
113440Atlassian Bitbucket 7.7.x < 7.17.12 命令注入
critical
113439Atlassian Bitbucket < 7.6.19 命令注入
critical
113434Atlassian Crowd < 4.4.4 错误配置
critical
113432HTMLawed < 1.2.9 命令注入
critical
113431Sitecore CMS/XP CSRF 远程代码执行
critical
113428已启用 WordPress Post By Email
info
113427Apache Commons Text 远程代码执行 (Text4Shell)
critical
113429Joomla! 4.x < 4.2.5 跨站脚本
medium
113426PHP 7.4.x < 7.4.33 多个漏洞
critical