# CVE 列表 此文件用于维护 DeepAudit 项目扫描并申报得到的 CVE 漏洞列表。 ## 统计概览 | 指标 | 数值 | |:---|:--:| | CVE 总数 | 49 | | 涉及项目 | 16 | | 漏洞类型 | 12 | ## 漏洞列表 | CVE | 项目名称 | 项目热度 | 漏洞类型 | CVSS | 发现者 | |:---|:---|:---:|:---|:----:|:---| | [CVE-2026-1884](https://nvd.nist.gov/vuln/detail/cve-2026-1884) | [Zentao PMS](https://github.com/easysoft/zentaopms) | [![Stars](https://img.shields.io/github/stars/easysoft/zentaopms?style=social)](https://github.com/easysoft/zentaopms/stargazers) | SSRF | 5.1 | ez-lbz | | [CVE-2025-13789](https://nvd.nist.gov/vuln/detail/CVE-2025-13789) | [Zentao PMS](https://github.com/easysoft/zentaopms) | [![Stars](https://img.shields.io/github/stars/easysoft/zentaopms?style=social)](https://github.com/easysoft/zentaopms/stargazers) | SSRF | 5.3 | ez-lbz | | [CVE-2025-13787](https://nvd.nist.gov/vuln/detail/CVE-2025-13787) | [Zentao PMS](https://github.com/easysoft/zentaopms) | [![Stars](https://img.shields.io/github/stars/easysoft/zentaopms?style=social)](https://github.com/easysoft/zentaopms/stargazers) | Privilege Escalation | 9.1 | ez-lbz | | [CVE-2025-64428](https://nvd.nist.gov/vuln/detail/CVE-2025-64428) | [Dataease](https://github.com/dataease/dataease) | [![Stars](https://img.shields.io/github/stars/dataease/dataease?style=social)](https://github.com/dataease/dataease/stargazers) | JNDI Injection | 9.8 | ez-lbz | | [CVE-2025-13246](https://nvd.nist.gov/vuln/detail/CVE-2025-13246) | [Modulithshop](https://github.com/shsuishang/modulithshop) | [![Stars](https://img.shields.io/github/stars/shsuishang/modulithshop?style=social)](https://github.com/shsuishang/modulithshop/stargazers) | SQL Injection | 6.3 | ez-lbz | | [CVE-2025-64163](https://nvd.nist.gov/vuln/detail/CVE-2025-64163) | [Dataease](https://github.com/dataease/dataease) | [![Stars](https://img.shields.io/github/stars/dataease/dataease?style=social)](https://github.com/dataease/dataease/stargazers) | SSRF | 9.8 | ez-lbz | | [CVE-2025-64164](https://nvd.nist.gov/vuln/detail/CVE-2025-64164) | [Dataease](https://github.com/dataease/dataease) | [![Stars](https://img.shields.io/github/stars/dataease/dataease?style=social)](https://github.com/dataease/dataease/stargazers) | JNDI Injection | 9.8 | ez-lbz | | [CVE-2025-11581](https://nvd.nist.gov/vuln/detail/CVE-2025-11581) | [PowerJob](https://github.com/PowerJob/PowerJob) | [![Stars](https://img.shields.io/github/stars/PowerJob/PowerJob?style=social)](https://github.com/PowerJob/PowerJob/stargazers) | Privilege Escalation | 7.5 | ez-lbz | | [CVE-2025-11580](https://nvd.nist.gov/vuln/detail/CVE-2025-11580) | [PowerJob](https://github.com/PowerJob/PowerJob) | [![Stars](https://img.shields.io/github/stars/PowerJob/PowerJob?style=social)](https://github.com/PowerJob/PowerJob/stargazers) | Privilege Escalation | 5.3 | ez-lbz | | [CVE-2025-10771](https://nvd.nist.gov/vuln/detail/CVE-2025-10771) | [Jimureport](https://github.com/jeecgboot/JimuReport) | [![Stars](https://img.shields.io/github/stars/jeecgboot/JimuReport?style=social)](https://github.com/jeecgboot/JimuReport/stargazers) | Deserialization | 9.8 | ez-lbz | | [CVE-2025-10770](https://nvd.nist.gov/vuln/detail/CVE-2025-10770) | [Jimureport](https://github.com/jeecgboot/JimuReport) | [![Stars](https://img.shields.io/github/stars/jeecgboot/JimuReport?style=social)](https://github.com/jeecgboot/JimuReport/stargazers) | Deserialization | 6.5 | ez-lbz | | [CVE-2025-10769](https://nvd.nist.gov/vuln/detail/CVE-2025-10769) | [H2o-3](https://github.com/h2oai/h2o-3) | [![Stars](https://img.shields.io/github/stars/h2oai/h2o-3?style=social)](https://github.com/h2oai/h2o-3/stargazers) | Deserialization | 9.8 | ez-lbz | | [CVE-2025-10768](https://nvd.nist.gov/vuln/detail/CVE-2025-10768) | [H2o-3](https://github.com/h2oai/h2o-3) | [![Stars](https://img.shields.io/github/stars/h2oai/h2o-3?style=social)](https://github.com/h2oai/h2o-3/stargazers) | Deserialization | 9.8 | ez-lbz | | [CVE-2025-58045](https://nvd.nist.gov/vuln/detail/CVE-2025-58045) | [Dataease](https://github.com/dataease/dataease) | [![Stars](https://img.shields.io/github/stars/dataease/dataease?style=social)](https://github.com/dataease/dataease/stargazers) | JNDI Injection | 9.8 | ez-lbz | | [CVE-2025-10423](https://nvd.nist.gov/vuln/detail/CVE-2025-10423) | [Newbee-mall](https://github.com/newbee-ltd/newbee-mall) | [![Stars](https://img.shields.io/github/stars/newbee-ltd/newbee-mall?style=social)](https://github.com/newbee-ltd/newbee-mall/stargazers) | Guessable Captcha | 3.7 | ez-lbz | | [CVE-2025-10422](https://nvd.nist.gov/vuln/detail/CVE-2025-10422) | [Newbee-mall](https://github.com/newbee-ltd/newbee-mall) | [![Stars](https://img.shields.io/github/stars/newbee-ltd/newbee-mall?style=social)](https://github.com/newbee-ltd/newbee-mall/stargazers) | Privilege Escalation | 4.3 | ez-lbz | | [CVE-2025-9835](https://nvd.nist.gov/vuln/detail/CVE-2025-9835) | [Mall](https://github.com/macrozheng/mall) | [![Stars](https://img.shields.io/github/stars/macrozheng/mall?style=social)](https://github.com/macrozheng/mall/stargazers) | Privilege Escalation | 4.3 | ez-lbz | | [CVE-2025-9737](https://nvd.nist.gov/vuln/detail/CVE-2025-9737) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9736](https://nvd.nist.gov/vuln/detail/CVE-2025-9736) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9735](https://nvd.nist.gov/vuln/detail/CVE-2025-9735) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9734](https://nvd.nist.gov/vuln/detail/CVE-2025-9734) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9719](https://nvd.nist.gov/vuln/detail/CVE-2025-9719) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9718](https://nvd.nist.gov/vuln/detail/CVE-2025-9718) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9717](https://nvd.nist.gov/vuln/detail/CVE-2025-9717) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9716](https://nvd.nist.gov/vuln/detail/CVE-2025-9716) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9715](https://nvd.nist.gov/vuln/detail/CVE-2025-9715) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9683](https://nvd.nist.gov/vuln/detail/CVE-2025-9683) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9682](https://nvd.nist.gov/vuln/detail/CVE-2025-9682) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9681](https://nvd.nist.gov/vuln/detail/CVE-2025-9681) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9680](https://nvd.nist.gov/vuln/detail/CVE-2025-9680) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9659](https://nvd.nist.gov/vuln/detail/CVE-2025-9659) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9658](https://nvd.nist.gov/vuln/detail/CVE-2025-9658) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9657](https://nvd.nist.gov/vuln/detail/CVE-2025-9657) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9655](https://nvd.nist.gov/vuln/detail/CVE-2025-9655) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9646](https://nvd.nist.gov/vuln/detail/CVE-2025-9646) | [O2oa](https://github.com/o2oa/o2oa) | [![Stars](https://img.shields.io/github/stars/o2oa/o2oa?style=social)](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-9602](https://nvd.nist.gov/vuln/detail/CVE-2025-9602) | [RockOA](https://github.com/rainrocka/xinhu) | [![Stars](https://img.shields.io/github/stars/rainrocka/xinhu?style=social)](https://github.com/rainrocka/xinhu/stargazers) | Database Backdoor | 6.5 | ez-lbz | | [CVE-2025-9514](https://nvd.nist.gov/vuln/detail/CVE-2025-9514) | [Mall](https://github.com/macrozheng/mall) | [![Stars](https://img.shields.io/github/stars/macrozheng/mall?style=social)](https://github.com/macrozheng/mall/stargazers) | Privilege Escalation | 3.7 | ez-lbz | | [CVE-2025-9264](https://nvd.nist.gov/vuln/detail/CVE-2025-9264) | [Xxl-job](https://github.com/xuxueli/xxl-job) | [![Stars](https://img.shields.io/github/stars/xuxueli/xxl-job?style=social)](https://github.com/xuxueli/xxl-job/stargazers) | Privilege Escalation | 5.4 | ez-lbz | | [CVE-2025-9263](https://nvd.nist.gov/vuln/detail/CVE-2025-9263) | [Xxl-job](https://github.com/xuxueli/xxl-job) | [![Stars](https://img.shields.io/github/stars/xuxueli/xxl-job?style=social)](https://github.com/xuxueli/xxl-job/stargazers) | Privilege Escalation | 4.3 | ez-lbz | | [CVE-2025-9241](https://nvd.nist.gov/vuln/detail/CVE-2025-9241) | [Eladmin](https://github.com/elunez/eladmin) | [![Stars](https://img.shields.io/github/stars/elunez/eladmin?style=social)](https://github.com/elunez/eladmin/stargazers) | CSV/XLSX Injection | 7.5 | ez-lbz | | [CVE-2025-9240](https://nvd.nist.gov/vuln/detail/CVE-2025-9240) | [Eladmin](https://github.com/elunez/eladmin) | [![Stars](https://img.shields.io/github/stars/elunez/eladmin?style=social)](https://github.com/elunez/eladmin/stargazers) | Sensitive Information Disclosure | 4.3 | ez-lbz | | [CVE-2025-9239](https://nvd.nist.gov/vuln/detail/CVE-2025-9239) | [Eladmin](https://github.com/elunez/eladmin) | [![Stars](https://img.shields.io/github/stars/elunez/eladmin?style=social)](https://github.com/elunez/eladmin/stargazers) | Hardcoded Credentials | 3.7 | ez-lbz | | [CVE-2025-8974](https://nvd.nist.gov/vuln/detail/CVE-2025-8974) | [Litemall](https://github.com/linlinjava/litemall) | [![Stars](https://img.shields.io/github/stars/linlinjava/litemall?style=social)](https://github.com/linlinjava/litemall/stargazers) | Hardcoded Credentials | 9.8 | ez-lbz | | [CVE-2025-8852](https://nvd.nist.gov/vuln/detail/CVE-2025-8852) | [Wukong CRM](https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA) | [![Stars](https://img.shields.io/github/stars/WuKongOpenSource/WukongCRM-11.0-JAVA?style=social)](https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/stargazers) | Sensitive Information Disclosure | 4.3 | ez-lbz | | [CVE-2025-8840](https://nvd.nist.gov/vuln/detail/CVE-2025-8840) | [Jsherp](https://github.com/jishenghua/jshERP) | [![Stars](https://img.shields.io/github/stars/jishenghua/jshERP?style=social)](https://github.com/jishenghua/jshERP/stargazers) | Privilege Escalation | 5.4 | ez-lbz | | [CVE-2025-8839](https://nvd.nist.gov/vuln/detail/CVE-2025-8839) | [Jsherp](https://github.com/jishenghua/jshERP) | [![Stars](https://img.shields.io/github/stars/jishenghua/jshERP?style=social)](https://github.com/jishenghua/jshERP/stargazers) | Privilege Escalation | 8.8 | ez-lbz | | [CVE-2025-8764](https://nvd.nist.gov/vuln/detail/CVE-2025-8764) | [Litemall](https://github.com/linlinjava/litemall) | [![Stars](https://img.shields.io/github/stars/linlinjava/litemall?style=social)](https://github.com/linlinjava/litemall/stargazers) | XSS | 5.4 | ez-lbz | | [CVE-2025-8753](https://nvd.nist.gov/vuln/detail/CVE-2025-8753) | [Litemall](https://github.com/linlinjava/litemall) | [![Stars](https://img.shields.io/github/stars/linlinjava/litemall?style=social)](https://github.com/linlinjava/litemall/stargazers) | Arbitrary File Deletion | 5.4 | ez-lbz | | [CVE-2025-8708](https://nvd.nist.gov/vuln/detail/CVE-2025-8708) | [White-Jotter](https://github.com/Antabot/White-Jotter) | [![Stars](https://img.shields.io/github/stars/Antabot/White-Jotter?style=social)](https://github.com/Antabot/White-Jotter/stargazers) | Deserialization | 7.5 | ez-lbz | --- 漏洞无先后顺序,默认按照从上到下的报送顺序排列,项目名称首字母大写。 如果您使用 DeepAudit 发现了漏洞,欢迎在 [Issues](https://github.com/lintsinghua/DeepAudit/issues/135) 中留言反馈。您的贡献将极大地丰富这份漏洞列表,非常感谢!