VYPR
Vendor

Xiandafu

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2024-22533CriFeb 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be…

  • CVE-2026-8759HigMay 17, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFunction.java of the component SpELFunction. The manipulation leads to improper…

  • CVE-2022-4347LowDec 8, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in xiandafu beetl-bbs. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file WebUtils.java. The manipulation of the argument user leads to cross site scripting. The attack can be launched remotely.…

  • CVE-2026-52439CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism