相关漏洞推荐 CVE-2025-53833: LaRecipe 模板注入漏洞(CVE-2025-53833) POC 2025-09-01 | LaRecipe fofa: body="LaRecipe" && body="/larecipe/" || body="/docs/1.0/overv... CVE-2025-53833: LaRecipe < 2.8.1 Remote Code Execution via SSTI POC 2025-08-01 | LaRecipe LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel ... Laravel LaRecipe renderBlade 未授权 代码注入漏洞 (CVE-2025-53833) 无POC 2025-07-16 | LaRecipe Laravel LaRecipe 存在模板注入漏洞,漏洞的技术原理在于 LaRecipe 的文档渲染模块采用了不安全的动态模板编译方式。具体而言,当系统解析Markdown 文档时,会直接通过 ren... Wordpress Plugin Depicter /wp-admin/admin-ajax.php depicter-lead-list SQL 注入漏洞(CVE-2025-2011) 无POC 2025-09-19 | Wordpress WordPress插件Depicter的滑块和弹出窗口构建器在包括3.6.1版本在内的所有版本中,由于用户提供的参数缺乏足够的转义处理和现有SQL查询的预处理不足,存在通用的SQL注入漏洞。该漏洞可以... Wordpress Plugin Eventin /wp-admin/admin-ajax.php proxy_image 文件读取漏洞(CVE-2025-3419) 无POC 2025-09-19 | Wordpress Event Manager, Events Calendar, Tickets, Registrations – Eventin 是一个用于 WordPress 的插件。该漏洞存在于其 proxy_i...