Chancms is a modestly represented content-management platform whose vulnerability profile skews toward serious outcomes, with a notable share reaching critical severity and a strong tendency toward public exploit availability. The exposure recurs through a characteristic set of injection and deserialization weaknesses—including SQL injection, output injection, server-side request forgery, code injection, and untrusted deserialization—that reflect the parsing and dynamic-execution demands of a web-based CMS architecture. Defenders should prioritize internet-facing instances of this platform and treat disclosed flaws as high-risk; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chancms over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-10210HIGH A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argume | Sep 10, 2025 | 8.8 | 39 | NO | YES |
CVE-2025-8227CRITICAL A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /collect/get | Jul 27, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-8226CRITICAL A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unknown function of the file /sysApp/find. The manipulation of | Jul 27, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-8266MEDIUM A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArticle of the file app/modules/cms | Jul 28, 2025 | 6.3 | 32 | NO | YES |
CVE-2025-10211MEDIUM A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulati | Sep 10, 2025 | 6.3 | 31 | NO | YES |
CVE-2025-65602CRITICAL A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request. | Dec 10, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-10106HIGH A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation of the argument keyword leads to | Sep 8, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-8228HIGH A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function getPages of the file /cms/collect/getPages. The | Jul 27, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-11905HIGH A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\controller\gather.js. The manipulation | Oct 17, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-10110HIGH A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html leads to | Sep 8, 2025 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chancms.
Media articles that mention a CVE ID that affects a product developed by Chancms — matched by CVE ID, not by vendor name.