CVE-2025-10211
- EPSS 0.04%
- Published 10.09.2025 20:15:33
- Last modified 15.09.2025 14:53:01
A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulation of the argument taskUrl leads to server-side request forgery. The a...
CVE-2025-10210
- EPSS 0.03%
- Published 10.09.2025 19:02:06
- Last modified 15.09.2025 14:53:19
A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launched remotely....
CVE-2025-10110
- EPSS 0.03%
- Published 08.09.2025 22:32:09
- Last modified 10.09.2025 16:41:18
A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html leads to sql injection. Remote exploitation of the attack is possible. The expl...
CVE-2025-10106
- EPSS 0.03%
- Published 08.09.2025 21:32:05
- Last modified 10.09.2025 18:06:28
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit has b...
CVE-2025-10105
- EPSS 0.03%
- Published 08.09.2025 20:32:07
- Last modified 10.09.2025 18:05:59
A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the file /cms/article/search. This manipulation of the argument keyword causes sql injection. The attack can be initiated remotely. The...
CVE-2025-8266
- EPSS 0.09%
- Published 28.07.2025 08:32:15
- Last modified 27.08.2025 16:24:18
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArticle of the file app/modules/cms/controller/collect.js. The manipulation of the argument targetUrl lea...
CVE-2025-8228
- EPSS 0.05%
- Published 27.07.2025 09:32:15
- Last modified 26.08.2025 14:06:11
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function getPages of the file /cms/collect/getPages. The manipulation of the argument targetUrl leads to server-side request f...
CVE-2025-8227
- EPSS 0.07%
- Published 27.07.2025 09:15:27
- Last modified 26.08.2025 14:06:22
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /collect/getArticle. The manipulation of the argument taskUrl leads to deserializa...
CVE-2025-8226
- EPSS 0.04%
- Published 27.07.2025 08:32:11
- Last modified 26.08.2025 14:07:08
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unknown function of the file /sysApp/find. The manipulation of the argument accessKey/secretKey leads to information disclosure. It i...
CVE-2025-8133
- EPSS 0.06%
- Published 25.07.2025 06:15:24
- Last modified 27.08.2025 16:24:35
A vulnerability classified as critical has been found in yanyutao0402 ChanCMS up to 3.1.2. This affects the function getArticle of the file app/modules/api/service/gather.js. The manipulation of the argument targetUrl leads to server-side request for...