Related VulnerabilitiesPoCCVE-2026-58123: Hermes WebUI < 0.51.788 - Remote Code ExecutionMLflow /api/2.0/mlflow/webhooks 服务器端请求伪造漏洞(CVE-2026-64849)PoCCVE-2026-64849: MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect BypassPoCCVE-2025-26399: SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCEPoCweb-config: Web Configuration File - DetectPoCafterlogic-path-disclosure: AfterLogic Aurora and WebMail Pro < 7.7.9 - Full Path DisclosurePoCibm-websphere-ssrf: IBM WebSphere HCL Digital Experience - Server-Side Request ForgeryPoCCVE-2025-13528: Feedback Modal for Website <= 1.0.1 - Unauthenticated Feedback ExportPoCCVE-2026-41432: New API < v0.12.10 - Stripe Webhook Bypass金和OA /c6/JHSoft.Web.CostControl/Decompose/AjaxForCenterBudgetDecompose.ashx SQL 注入漏洞金和OA /c6/JHSoft.Web.CostControl/BudgetExecution/VouchUpdate.aspx SQL 注入漏洞MicroweberCMS userfiles x存在路径穿越漏洞(CVE-2026-65694)Open WebUI /api/v1/retrieval/process/web 服务器端请求伪造漏洞(CVE-2026-70485)