VYPR

ChanCMS

by Yanyutao0402

CVEs (8)

  • CVE-2025-11905MedOct 17, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\controller\gather.js. The manipulation results in code injection. The attack may be launched remotely. The exploit has been made public…

  • CVE-2025-11904MedOct 17, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…

  • CVE-2025-11903MedOct 17, 2025
    risk 0.41cvss 6.3epss 0.01

    A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing a manipulation of the argument cid can lead to sql injection. The attack can be launched remotely. The exploit has been published…

  • CVE-2025-11902MedOct 17, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findField of the file /cms/article/findField. Performing a manipulation of the argument cid results in sql injection. The attack can be initiated remotely. The…

  • CVE-2025-10211MedSep 10, 2025
    risk 0.41cvss 6.3epss 0.01

    A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulation of the argument taskUrl leads to server-side request forgery. The attack may be initiated…

  • CVE-2025-10210MedSep 10, 2025
    risk 0.41cvss 6.3epss 0.01

    A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launched remotely. The exploit has been made…

  • CVE-2025-10106MedSep 8, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public…

  • CVE-2025-10105MedSep 8, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the file /cms/article/search. This manipulation of the argument keyword causes sql injection. The attack can be initiated remotely. The exploit has been published…