CVE-2025-11905
- EPSS 0.75%
- Veröffentlicht 17.10.2025 15:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\controller\gather.js. The manipulation results in code injection. The attack may be launched remotely. The e...
CVE-2025-11904
- EPSS 0.6%
- Veröffentlicht 17.10.2025 15:02:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been...
CVE-2025-11903
- EPSS 0.58%
- Veröffentlicht 17.10.2025 14:15:46
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing a manipulation of the argument cid can lead to sql injection. The attack can be launched remotely. The...
CVE-2025-11902
- EPSS 0.58%
- Veröffentlicht 17.10.2025 14:15:45
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findField of the file /cms/article/findField. Performing a manipulation of the argument cid results in sql injection. The attack can be i...
CVE-2025-10211
- EPSS 0.66%
- Veröffentlicht 10.09.2025 20:15:33
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulation of the argument taskUrl leads to server-side request forgery. The a...
CVE-2025-10210
- EPSS 1.2%
- Veröffentlicht 10.09.2025 19:02:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launched remotely....
CVE-2025-10106
- EPSS 0.35%
- Veröffentlicht 08.09.2025 21:32:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit has b...
CVE-2025-10105
- EPSS 0.31%
- Veröffentlicht 08.09.2025 20:32:07
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the file /cms/article/search. This manipulation of the argument keyword causes sql injection. The attack can be initiated remotely. The...