yansongda CVE 脆弱性と CVE 一覧(1)

製品(CPE): — CVE 件数: 1

yansongda 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to yansongda, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 11 / 1 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-33661 Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `verify_wechat_sign()` function in `src/Functions.php` unconditionally skips all signature verification when the PSR-7 request reports `localhost` as the host. An attacker can exploit this by sending a crafted HTTP request to the WeChat Pay callback endpoint with a `Host: localhost` header, bypassing the RSA signature check entirely. This allows forging fake WeChat Pay payment s [email protected] 8.6 0.01% 2026-03-26 2026-04-01
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence