References https://github.com/Phuong39/2022-HW-POC/blob/main/%E7%94%A8%E5%8F%8B%E6%97%B6%E7%A9%BAKSOA%E8%BD%AF%E4%BB%B6%E5%89%8D%E5%8F%B0%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://www.ddpoc.com/DVB-2022-3803.html https://www.cnblogs.com/pursue-security/p/17687951.html https://blog.csdn.net/weixin_60329350/article/details/133032559 https://cn-sec.com/archives/2193697.html https://github.com/gallopsec/YY-SK-KASO https://cn-sec.com/archives/1329088.html https://blog.csdn.net/weixin_43981050/article/details/131324174 https://buaq.net/go-158208.html https://blog.csdn.net/weixin_53884648/article/details/130811353 https://www.cnblogs.com/yang-miemie/p/17714927.html
Related VulnerabilitiesPoCCVE-2026-0692: BlueSnap Payment Gateway for WooCommerce <=3.4.0 - IPN Authorization BypassPoCCVE-2026-29058: WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command InjectionPoCXboot /xboot/common/swagger/login 服务器端请求伪造漏洞PoCCVE-2025-34033: Blue Angel Software Suite (5V Technologies) - OS Command InjectionPoCCVE-2026-12227: Visual Composer <= 45.16.0 - Unauthenticated LFIPoCCVE-2026-49060: Hippoo Mobile App for WooCommerce - Broken Access Control全景軟體|CGServiSign - OS Command InjectionPoCCVE-2026-0702: VidShop for WooCommerce <= 1.1.4 - SQL InjectionPoCCVE-2026-81578: PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-DirectPoCjohnson-controls-default-login: Johnson Controls Frick Quantum HD Compressors - Default LoginJoomShaper SP LMS /index.php?option=com_splms&view=cart 文件上传漏洞(CVE-2026-48909)綠色運算|NUMail - OS Command InjectionPoCCVE-2026-11387: SMS Alert – SMS & OTP for WooCommerce - Privilege Escalation