References https://www.twcert.org.tw/tw/cp-132-10170-e2435-1.html https://tp2rc.tanet.edu.tw/node/1054 https://lic.nuk.edu.tw/p/406-1012-89134,r73.php?Lang=zh-tw https://www.twcert.org.tw/tw/lp-132-1-6-20.html https://www.cvedetails.com/cve/CVE-2025-5894/ https://net.cyut.edu.tw/acl/message.php https://www.twcert.org.tw/tw/dl-387-2d0cb91302c146d5baca78b53cf7e470.html https://net.nthu.edu.tw/netsys/en:mailing:announcement:20250611_01?do=export_pdf https://www.openinfosec.com/zh/shareArticle/content/1121
Related VulnerabilitiesPoCCVE-2026-27454: Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization BypassPoCCVE-2026-53595: FreeScout < 1.8.224 - Invite Hash Authorization Bypass鎧應科技|CAYIN CMS-WS/CMS-SE - Missing AuthenticationPoCCVE-2025-14047: User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment Deletion網韻資訊|NewSiteServer (NSS) 新式校園網站系統 - Missing AuthenticationPoCCVE-2026-34976: Dgraph <=v25.3.0 - Admin Mutation Missing AuthorizationPoCCVE-2026-61808: LightRAG <= 1.5.4 - Missing Authentication葆光系統|POS餐飲系統 - Missing AuthenticationPoCCVE-2026-1830: Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File UploadPoCCVE-2026-22683: Windmill < 1.603.3 - Operator Authorization BypassPoCCVE-2026-3335: Canto <= 3.1.1 - Missing Authorization to Unauthenticated File UploadPoCCVE-2026-42569: phpVMS < 7.0.6 - Legacy Importer Authorization Bypass