相关漏洞推荐 POC CVE-2018-7765: Schneider Electric U.motion Builder - SQL Injection POC CVE-2020-19363: Vtiger CRM v7.2.0 - Directory Listing POC CVE-2021-28799: QNAP HBS 3 - Broken Access Control POC CVE-2021-37598: WP Cerber < 8.9.3 - Broken Access Control POC CVE-2022-37932: HP Switch - Authentication Bypass POC CVE-2024-29137: WordPress Tourfic Plugin <= 2.11.7 - Cross-Site Scripting POC CVE-2024-29792: Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting POC CVE-2025-25570: Vue Vben Admin - Default Credentials POC wp-contact-form-7-fpd: WordPress Contact Form 7 - Full Path Disclosure 用友Bip /bi/api/Portal/LoginWithV8 目录遍历漏洞(CVE-2025-66744) ComfyUI /api/customnode/install/git_url 代码执行漏洞(CVE-2025-67303) Cal.com /api/auth/session 权限绕过漏洞(CVE-2026-23478) MindsDB /api/sql/query 未授权访问漏洞(CVE-2025-68472)