相关漏洞推荐 微力同步 /rest/f/api/resources/f96956469e7be39d 文件读取漏洞 Frappe /api/method/frappe.automation.doctype.auto_repeat.auto_repeat.generate_message_preview SQL 注入漏洞(CVE-2025-68929) phpMyFAQ /api/setup/backup 信息泄露漏洞(CVE-2025-69200) Yealink T53 Phone /api/auth/login 默认口令漏洞 POC JNPF快速开发平台 /api/file/Image/userAvatar/aa 文件读取漏洞 ERPNext /api/method/erpnext.crm.doctype.contract_template.contract_template.get_contract_template SQL 注入漏洞(CVE-2025-66435) ERPNext /api/method/erpnext.accounts.doctype.dunning.dunning.get_dunning_letter_text SQL 注入漏洞(CVE-2025-66434) 微力同步 /rest/f/api/raw/f96956469e7be39d 文件读取漏洞(CVE-2025-14197) POC CVE-2024-28253: OpenMetaData - SpEL Injection in PUT /api/v1/policies go-ldap-admin /api/log/operation/list 权限绕过漏洞(CVE-2025-13948) 用友 U8Cloud /u8cloud/api/hrta/returnaway/submit SQL 注入漏洞 Ceph /api/auth 默认口令漏洞 Langflow /api/v1/files/profile_pictures/../langflow.db 目录遍历漏洞