Related VulnerabilitiesPoCCVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function Invocation仁和兴业(深圳)软件有限公司仁和云ERP weChatAppletgetGoodsList.action 存在SSRF漏洞仁和兴业(深圳)软件有限公司仁和云ERP purchaseOrdersaveOrderApplet.action存在反序列化漏洞PoCCVE-2026-46442: Flowise < 3.1.2 - node-custom-function Unauthorized RCENuclio /api/functions 文件上传漏洞 Nuclio /api/functions runtimeAttributes.repositories 命令执行漏洞(CVE-2026-52833)FlowiseAI Flowise /api/v1/node-custom-function 代码执行漏洞(CVE-2026-46442)Hepta Platforms|Heptabase - Exposed Dangerous Method or FunctionPoCCVE-2024-38819: Spring Framework Path Traversal in Functional Web FrameworksPoCazure-functions-hostjson-exposure: Azure Functions host.json Configuration Exposure关于U8cloud所有版本u8capplet.jsp存在XSS漏洞的安全公告PoCfunctions-php-disclosure: functions.php Full Path DisclosureSIM /api/function/execute 代码执行漏洞