Related VulnerabilitiesWordPress YARPP /includes/yarpp_pro_set_display_types.php 权限绕过漏洞 (CVE-2024-43919)WordPress Ditty /wp-json/dittyeditor/v1/displayItems 服务器端请求伪造漏洞(CVE-2025-8085)Ditty WordPress插件displayItems端点未授权访问漏洞thinkcmf-lfi: Thinkcmf lfithinkcmf-write-shell: Thinkcmf write shellPoCdisplay-last-username-enabled: Do Not Display Last User Name DisabledPoCthinkcmf-file-include: thinkCMF 文件包含PoCCVE-2020-20601: ThinkCMF X2.2.2 - Remote Code ExecutionPoCexposed-sqlite-manager: SQLiteManager - Text DisplayPoCthinkcmf-lfi: ThinkCMF - Local File InclusionPoCthinkcmf-rce: ThinkCMF - Remote Code Execution宏景eHR /templates/attestation/../../servlet/DisplayOleContent 文件读取漏洞