Related VulnerabilitiesPoCCVE-2026-71362: Adobe Commerce/Magento - Customer Session Identity SwitchLangflow /api/v1/custom_component 代码执行漏洞(CVE-2024-37014)PoCCVE-2026-1980: WPBookit <= 1.0.8 - Unauthenticated Customer Information DisclosurePoCCVE-2026-46442: Flowise < 3.1.2 - node-custom-function Unauthorized RCEFlowiseAI Flowise /api/v1/node-custom-function 代码执行漏洞(CVE-2026-46442) WordPress MyStyle Custom Product Designer /designs/ SQL 注入漏洞(CVE-2025-48281)天地伟业Easy7 /Easy7/rest/file/uploadCustomIcon 文件上传漏洞PoCCVE-2026-6433: FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code Execution月子会所ERP管理云平台GetCustomerCenterReceiveList存在SQL注入漏洞PoCretool-postmessage-xss: Retool Self-Hosted - postMessage XSS via Custom Component CollectionsPoC孚盟云 CRM /m/Dingding/CustomizeReport/CustomizeReportSelectMould.aspx SQL 注入漏洞用友 NC /uapws/service/nc.itf.bd.crm.ICustomerImportToNcService XML 外部实体注入漏洞用友 NC /uapws/service/nc.itf.bd.crm.ICustomerExportToCrmService XML 外部实体注入漏洞