References https://github.com/adysec/POC/blob/main/wpoc/%E9%93%AD%E9%A3%9E/%E9%93%AD%E9%A3%9ECMS-search%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://www.cnblogs.com/LeouMaster/p/18214033 https://gitee.com/mingSoft/MCMS/issues/I4W1S9 https://avd.aliyun.com/detail?id=AVD-2022-25125 https://www.cnvd.org.cn/flaw/show/CNVD-2022-15490 https://www.wlaqsys.com/archives/12816 https://www.ddpoc.com/DVB-2023-4123.html https://www.sentinelone.com/vulnerability-database/cve-2026-4954/
Related VulnerabilitiesPoCCVE-2026-59509: cve-search 4.0-6.0.0 - Unauthenticated NoSQL InjectionCloudreve网盘 /api/v3/share/search 未授权访问漏洞Piwigo /ws.php pwg.history.search 未授权访问漏洞(CVE-2026-27833)WordPress WP-Advanced-Search /autocompletion-PHP5.5.php SQL 注入漏洞(CVE-2024-9796)MLflow /ajax-api/3.0/jobs/search 权限绕过漏洞 (CVE-2026-2652)深信服运维安全管理系统 /fort/login/search_login 信息泄露漏洞SillyTavern /api/search/searxng 服务器端请求伪造漏洞(CVE-2026-46372)用友KSOA search_list.jsp 存在sql注入漏洞PoCCVE-2026-42031: CKAN DataStore SQL Search - SQL InjectionCKAN /api/action/datastore_search_sql SQL 注入漏洞(CVE-2026-42031)用友NC Cloud /ncchr/pm/ref/indiIssued/blobRefClassSearch 代码执行漏洞PoCCVE-2025-71258: BMC FootPrints 'searchWeb' - Server-Side Request Forgery东胜物流软件 HtmlSearchServiceLCL.aspx 存在SQL注入漏洞