VYPR
Critical severity9.8NVD Advisory· Published Dec 10, 2025· Updated Jun 17, 2026

CVE-2025-65602

CVE-2025-65602

Description

A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Chancms/Chancms3 versions
    cpe:2.3:a:chancms:chancms:3.3.4:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:chancms:chancms:3.3.4:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: <3.3.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.