目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

cms 产品漏洞列表 / CVE 中文分析 257

cms 产品相关 257 条漏洞,AI 中文标题与摘要、CVSS、POC 一站汇总。

本文档是内容管理系统(CMS)相关漏洞的聚合页面。本页面收录了近年来全球主流及开源 CMS 平台披露的安全缺陷,涵盖 SQL 注入、跨站脚本、任意文件读取及远程代码执行等高危弱点,时间范围覆盖过去数年间的历史数据与最新公告。通过查阅此页,安全研究人员可高效追踪特定厂商的修复进度,深入分析某类技术弱点的演变趋势,或快速检索某款产品在发布周期内的所有历史漏洞详情,为系统加固与风险评估提供全面参考。

ベンダー: Mambo

CVE IDタイトルCVSS深刻度公開日
CVE-2026-28425 Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs CWE-94 8.0 High2026-02-27
CVE-2026-28424 Statamic's missing authorization allows access to email addresses CWE-862 6.5 Medium2026-02-27
CVE-2026-28423 Statamic Vulnerable to Server-Side Request Forgery via Glide CWE-918 6.8 Medium2026-02-27
CVE-2026-27939 Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass CWE-287 8.8 High2026-02-27
CVE-2026-27593 Statamic is vulnerable to account takeover via password reset link injection CWE-640 9.3 Critical2026-02-24
CVE-2026-27129 Cloud Metadata SSRF Protection Bypass via IPv6 Resolution CWE-918 7.1AIHighAI2026-02-24
CVE-2026-27128 Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limit CWE-367 5.3AIMediumAI2026-02-24
CVE-2026-27127 Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding CWE-367 5.9 -2026-02-24
CVE-2026-27126 Craft CMS has Stored XSS in Table Field via "HTML" Column Type CWE-79 4.8AIMediumAI2026-02-24
CVE-2026-2934 YiFang CMS Extended Management D_friendLinkGroup.php update cross site scripting CWE-79 2.4 Low2026-02-22
CVE-2026-2933 YiFang CMS Extended Management D_adManage.php update cross site scripting CWE-79 2.4 Low2026-02-22
CVE-2026-2932 YiFang CMS Extended Management D_adPosition.php update cross site scripting CWE-79 2.4 Low2026-02-22
CVE-2026-27196 Statamic affected by privilege escalation via stored Cross-site Scripting CWE-79 8.1 High2026-02-21
CVE-2026-25759 Statmatic affected by privilege escalation via stored cross-site scripting CWE-79 8.7 High2026-02-11
CVE-2026-25633 Statamic's missing authorization allows access to assets CWE-862 4.3 Medium2026-02-11
CVE-2025-6967 Authentication Bypass in Sarman Soft's CMS CWE-698 8.7 High2026-02-10
CVE-2026-25498 Craft has a potential authenticated Remote Code Execution via malicious attached Behavior CWE-470 7.2AIHighAI2026-02-09
CVE-2026-25497 Craft has a GraphQL Asset Mutation Privilege Escalation CWE-639 8.8AIHighAI2026-02-09
CVE-2026-25496 Craft has a stored XSS in Number Prefix & Suffix Fields CWE-79 5.4AIMediumAI2026-02-09
CVE-2026-25495 Craft has a SQL Injection in Element Indexes via criteria[orderBy] CWE-89 8.8AIHighAI2026-02-09
CVE-2026-25494 Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation CWE-918 7.5AIHighAI2026-02-09
CVE-2026-25493 Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirect CWE-918 9.1AICriticalAI2026-02-09
CVE-2026-25492 Craft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying host CWE-918 6.5AIMediumAI2026-02-09
CVE-2026-25491 Craft has a Stored XSS in Entry Types Name CWE-79 5.4AIMediumAI2026-02-09
CVE-2025-68456 Unauthenticated Craft CMS users can trigger a database backup CWE-770 9.1 -2026-01-05
CVE-2025-68455 Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior CWE-470 7.2 -2026-01-05
CVE-2025-68454 Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI CWE-1336 7.2 -2026-01-05
CVE-2025-68437 Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation CWE-918 9.1 -2026-01-05
CVE-2025-68436 Craft CMS vulnerable to potential information disclosure via unchecked asset relocation CWE-200 6.5 -2026-01-05
CVE-2025-64112 Statmatic vulnerable to Stored Cross-Site Scripting CWE-79 8.0 High2025-10-30

cms 产品累计公开 257 条 CVE 漏洞,本页提供按时间倒序的完整列表,包含 CVSS、CWE、AI 中文摘要与可获取的 POC 链接。