References https://wpscan.com/vulnerability/8b51dc46-62c8-45b5-96ce-fb774b430388/ https://www.cve.org/CVERecord?id=CVE-2025-5209 https://github.com/advisories/GHSA-5j6c-8mh7-5662 https://patchstack.com/database/wordpress/plugin/add-search-to-menu/vulnerability/wordpress-ivory-search-plugin-5-5-10-admin-stored-xss-vulnerability https://hossted.com/knowledge-base/newsflash/business-and-enterprise-solutions/cms/wordpress-cross-site-scripting-vulnerability-in-ivory-search-plugin/ https://nvd.nist.gov/vuln/detail/CVE-2025-5209
Related VulnerabilitiesPoCCVE-2026-59509: cve-search 4.0-6.0.0 - Unauthenticated NoSQL InjectionCloudreve网盘 /api/v3/share/search 未授权访问漏洞Piwigo /ws.php pwg.history.search 未授权访问漏洞(CVE-2026-27833)WordPress WP-Advanced-Search /autocompletion-PHP5.5.php SQL 注入漏洞(CVE-2024-9796)MLflow /ajax-api/3.0/jobs/search 权限绕过漏洞 (CVE-2026-2652)深信服运维安全管理系统 /fort/login/search_login 信息泄露漏洞SillyTavern /api/search/searxng 服务器端请求伪造漏洞(CVE-2026-46372)用友KSOA search_list.jsp 存在sql注入漏洞PoCCVE-2026-42031: CKAN DataStore SQL Search - SQL InjectionCKAN /api/action/datastore_search_sql SQL 注入漏洞(CVE-2026-42031)用友NC Cloud /ncchr/pm/ref/indiIssued/blobRefClassSearch 代码执行漏洞PoCCVE-2025-71258: BMC FootPrints 'searchWeb' - Server-Side Request Forgery东胜物流软件 HtmlSearchServiceLCL.aspx 存在SQL注入漏洞