References https://ddpoc.com/DVB-2025-9599.html https://nosec.org/m/share/5892.html https://cn-sec.com/archives/4294684.html https://www.ddpoc.com/DVB-2025-9598.html https://ddpoc.com/DVB-2025-9491.html https://www.ddpoc.com/DVB-2025-9313.html
Related VulnerabilitiesPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCCVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDOR关于用友GRP-U8Cloud产品getUsersList及getNoteCode存在信息泄露漏洞的安全通告仁和兴业(深圳)软件有限公司仁和云ERP userresetPassword.action 存在任意账号密码重置漏洞PoCCVE-2025-14047: User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment DeletionPoCCVE-2026-15826: User Profile Builder 3.16.4 - Unauthenticated Authentication BypassMicroweberCMS userfiles x存在路径穿越漏洞(CVE-2026-65694)雨诺调度客户端 UserList 存在未授权访问敏感信息泄露漏洞PoCCVE-2025-6389: Sneeit WP Social WordPress Plugin - Unauthenticated RCE via call_user_funcDatart /api/v1/users/login 默认口令漏洞PoC喰星云数字化餐饮服务系统 /chainsales/head/user/addUser 权限绕过漏洞Goploy /user/login 默认口令漏洞