Related VulnerabilitiesPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2025-57231: Docmost 0.2.1-0.21.0 - Arbitrary File ReadPoCCVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDOR上海小羚羊软件股份有限公司小羚羊ERP系统downloadView存在任意文件读取漏洞PoCCVE-2022-39258: Mailcow Dockerized Swagger UI - Cross-Site Scripting仁和兴业(深圳)软件有限公司仁和云ERP attachmentdownloadAttachment 接口存在任意文件读取漏洞美麗島安全科技|4MOSAn GCB Doctor - OS Command InjectionPoCCVE-2026-8237: Concrete CMS <= 9.5.0 - Unauthenticated Conversation Message Disclosure (IDOR)itC 中心管理服务器actionDetailTmpFile.do 存在任意文件上传漏洞PoCCVE-2026-20896: Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication BypassPoCCVE-2025-0520: ShowDoc - Remote Code ExecutionPoCCVE-2026-71362: Adobe Commerce/Magento - Customer Session Identity SwitchPoCnodogsplash-lfi: Nodogsplash - Directory Traversal