相关漏洞推荐 Apache Struts XWork组件 XML外部实体注入漏洞(CVE-2025-68493) MindsDB /api/sql/query 未授权访问漏洞(CVE-2025-68472) WordPress Yoco Payments plugin /wp-json/yoco/logs 目录遍历漏洞(CVE-2025-13801) Frappe /api/method/frappe.automation.doctype.auto_repeat.auto_repeat.generate_message_preview SQL 注入漏洞(CVE-2025-68929) Frappe /files 目录遍历漏洞(CVE-2025-68953) POC CVE-2012-10018: WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Upload POC CVE-2024-24882: Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation POC CVE-2024-29138: WordPress Restrict User Access <= 2.5 - Cross-Site Scripting POC CVE-2025-60188: Atarim < 4.2.2 - Sensitive Information Exposure POC wp-jetpack-ssrf: Wordpress Jetpack plugin - Server Side Request Forgery POC CVE-2015-8350: WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS POC CVE-2017-18580: WordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Execution POC CVE-2018-10245: AWStats <= 7.5 - Full Path Disclosure