CVE-2025-8266
- EPSS 0.15%
- Veröffentlicht 28.07.2025 08:32:15
- Zuletzt bearbeitet 27.08.2025 16:24:18
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArticle of the file app/modules/cms/controller/collect.js. The manipulation of the argument targetUrl lea...
CVE-2025-8228
- EPSS 0.06%
- Veröffentlicht 27.07.2025 09:32:15
- Zuletzt bearbeitet 26.08.2025 14:06:11
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function getPages of the file /cms/collect/getPages. The manipulation of the argument targetUrl leads to server-side request f...
CVE-2025-8227
- EPSS 0.1%
- Veröffentlicht 27.07.2025 09:15:27
- Zuletzt bearbeitet 26.08.2025 14:06:22
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /collect/getArticle. The manipulation of the argument taskUrl leads to deserializa...
CVE-2025-8226
- EPSS 0.05%
- Veröffentlicht 27.07.2025 08:32:11
- Zuletzt bearbeitet 26.08.2025 14:07:08
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unknown function of the file /sysApp/find. The manipulation of the argument accessKey/secretKey leads to information disclosure. It i...
CVE-2025-8133
- EPSS 0.08%
- Veröffentlicht 25.07.2025 06:15:24
- Zuletzt bearbeitet 27.08.2025 16:24:35
A vulnerability classified as critical has been found in yanyutao0402 ChanCMS up to 3.1.2. This affects the function getArticle of the file app/modules/api/service/gather.js. The manipulation of the argument targetUrl leads to server-side request for...
CVE-2025-8132
- EPSS 0.15%
- Veröffentlicht 25.07.2025 05:15:37
- Zuletzt bearbeitet 27.08.2025 16:25:09
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function delfile of the file app/extend/utils.js. The manipulation leads to path traversal. The attack may be launched remotel...