VYPR
Vendor

Bestfeng

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2025-60267MedOct 9, 2025
    risk 0.42cvss 6.5epss 0.00

    In xckk v9.6, there is a SQL injection vulnerability in which the cond parameter in notice/list is not securely filtered, resulting in a SQL injection vulnerability.

  • CVE-2025-60266MedOct 9, 2025
    risk 0.42cvss 6.5epss 0.00

    In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in address/list is not securely filtered, resulting in a SQL injection vulnerability.

  • CVE-2025-60265MedOct 9, 2025
    risk 0.42cvss 6.5epss 0.00

    In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in user/list is not securely filtered, resulting in a SQL injection vulnerability.

  • CVE-2025-13209MedNov 15, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument writeProp causes xml…