目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

dFactory 厂商漏洞列表 / CVE 中文分析 14

dFactory 厂商相关 14 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

dFactory 是一个专注于软件开发工具链的厂商,其产品主要用于代码管理和持续集成流程。历史上,该厂商的产品曾频繁出现远程代码执行(RCE)和跨站脚本(XSS)漏洞,部分版本存在权限绕过问题。截至最新统计,其产品已累计披露14个CVE漏洞,主要集中在身份验证和输入验证环节。安全社区建议用户及时更新至最新版本,并实施最小权限原则以降低潜在风险。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-39616 WordPress Download Attachments plugin <= 1.4.0 - Insecure Direct Object References (IDOR) vulnerability — Download AttachmentsCWE-639 5.3 Medium2026-04-08
CVE-2026-2479 Responsive Lightbox & Gallery <= 2.7.1 - Authenticated (Author+) Server-Side Request Forgery via Remote Library Image Upload — Responsive Lightbox & GalleryCWE-918 5.0 Medium2026-02-25
CVE-2025-12359 Responsive Lightbox & Gallery <= 2.5.3 - Authenticated (Author+) Server-Side Request Forgery — Responsive Lightbox & GalleryCWE-918 5.4 Medium2025-11-19
CVE-2025-62941 WordPress Events Maker by dFactory plugin <= 1.6.14 - Cross Site Scripting (XSS) vulnerability — Events Maker by dFactoryCWE-79 6.5 Medium2025-10-27
CVE-2025-49995 WordPress Download Attachments plugin <= 1.3.1 - Insecure Direct Object References (IDOR) vulnerability — Download AttachmentsCWE-639 5.3 Medium2025-06-20
CVE-2024-43924 WordPress Responsive Lightbox & Gallery plugin <= 2.4.7 - Broken Access Control vulnerability — Responsive LightboxCWE-862 5.3 Medium2024-10-23
CVE-2024-49282 WordPress Responsive Lightbox & Gallery plugin <= 2.4.8 - Cross Site Scripting (XSS) vulnerability — Responsive LightboxCWE-79 5.9 Medium2024-10-17
CVE-2024-6870 Responsive Lightbox & Gallery <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via File Upload — Responsive Lightbox & GalleryCWE-79 6.4 Medium2024-08-22
CVE-2024-31252 WordPress Responsive Lightbox & Gallery plugin <= 2.4.6 - Broken Access Control vulnerability — Responsive LightboxCWE-862 4.3 Medium2024-06-09
CVE-2024-3230 Download Attachments <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting — Download AttachmentsCWE-79 6.4 Medium2024-06-04
CVE-2024-31264 WordPress Post Views Counter plugin <= 1.4.4 - Cross Site Request Forgery (CSRF) vulnerability — Post Views CounterCWE-352 4.3 Medium2024-04-12
CVE-2024-1994 Image Watermark <= 1.7.3 - Missing Authorization to Authenticated (Subscriber+) Watermark Modification — Image WatermarkCWE-862 4.3 Medium2024-04-06
CVE-2023-49174 WordPress Responsive Lightbox Plugin <= 2.4.5 is vulnerable to Cross Site Scripting (XSS) — Responsive Lightbox & GalleryCWE-79 5.9 Medium2023-12-15
CVE-2017-2243 WordPress Responsive Lightbox 跨站脚本漏洞 — Responsive Lightbox 6.1 -2017-07-07

本页汇总了 dFactory 厂商截至目前公开的全部 14 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。