References https://www.manageengine.com/network-monitoring/security-updates/cve-2022-29535.html https://nvd.nist.gov/vuln/detail/CVE-2022-29535 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29535 https://github.com/advisories/GHSA-4vf5-v3wq-vqr9 https://www.appsecure.security/vulnerability-database/cve-2022-29535/ https://devhub.checkmarx.com/cve-details/cve-2022-29535/ https://cxsecurity.com/cveproduct/9799/7412/manageengine_opmanager/
Related VulnerabilitiesPoCCVE-2019-1003030: Jenkins Pipeline Groovy Plugin <=2.63 - Insecure DeserializationPoCCVE-2026-3001: Gutenverse Plugin <= 3.4.6 - Cross-Site ScriptingPoCCVE-2025-6389: Sneeit WP Social WordPress Plugin - Unauthenticated RCE via call_user_funcPoCCVE-2026-3296: Everest Forms WordPress Plugin <= 3.4.3 - PHP Object InjectionPoCNginxWebUI /adminPage/login/getAuth 命令执行漏洞PoCNginxWebUI /Adminpage/Conf/loadOrg 文件读取漏洞NginxWebUI /Api/Nginx/runNginxCmd 命令执行漏洞NginxWebUI /Adminpage/Remote/cmdOver 命令执行漏洞Stripe Payment Plugin for WooCommerce /wc-api/WT_Stripe/ SQL 注入漏洞(CVE-2024-0705)NGINX ngx_http_rewrite_module 堆缓冲区溢出漏洞PoCCVE-2025-48157: WordPress Formality Plugin <= 1.5.9 - Local File InclusionPoCCVE-2025-58226: WordPress 3D FlipBook Plugin <= 1.16.17 - Sensitive Information ExposurePoCCVE-2026-40308: My Calendar WordPress Plugin - Information Disclosure