VYPR

Dingfanzu

by Geeeeeeeek

CVEs (3)

  • CVE-2025-28100CriApr 15, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.

  • CVE-2024-8302MedAug 29, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax/chpwd.php. The manipulation of the argument username leads to sql injection. The…

  • CVE-2024-48341LowSep 8, 2025
    risk 0.24cvss 3.7epss 0.00

    dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop