Description Adobe Commerce and Magento Open Source中存在存储型跨站脚本漏洞。该漏洞是由于在结帐页面上显示给用户的传输策略中对用户数据进行了不正确的清理。
Related VulnerabilitiesPoCCVE-2026-0702: VidShop for WooCommerce <= 1.1.4 - SQL InjectionPoCnuget-config-exposure: NuGet.config Package Source Credentials - ExposurePoCCVE-2026-11387: SMS Alert – SMS & OTP for WooCommerce - Privilege EscalationPoCCVE-2026-71362: Adobe Commerce/Magento - Customer Session Identity SwitchPoCCVE-2026-27542: WooCommerce Wholesale Lead Capture <= 2.0.3.1 - Unauthenticated Privilege EscalationPoCCVE-2026-3891: Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload北京中科聚网一体化运营平台 /manage/tplresource/importVisualModuleImg 文件上传漏洞东胜物流软件 /PriceCarrier/OpSailingDateInfoGridSource.aspx SQL 注入漏洞东胜物流软件 /PriceCarrier/CrmProxyMailListHtmlGridSource.aspx SQL 注入漏洞JeecgBoot 积木报表 /jmreport/getDataSourceByPage 信息泄露漏洞PoCCVE-2026-48282: Adobe ColdFusion - RDS Arbitrary File WriteStripe Payment Plugin for WooCommerce /wc-api/WT_Stripe/ SQL 注入漏洞(CVE-2024-0705)XWiki /xwiki/rest/liveData/sources/liveTable/entries SQL 注入漏洞(CVE-2025-32429)