Chyrp is a lightweight, open-source blogging platform whose vulnerability profile concentrates in its core product and reflects common risks in web application frameworks: cross-site scripting, path traversal, and SQL injection arising from input handling and query construction. While the vendor's disclosures remain modest in volume, public exploit code has frequently emerged for its vulnerabilities, making patch deployment and defensive filtering a practical priority for deploying sites. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chyrp over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2744MEDIUM Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action pa | Jul 19, 2011 | 6.8 | 43 | NO | YES |
CVE-2011-2780MEDIUM Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a differ | Jul 19, 2011 | 5.0 | 40 | NO | YES |
CVE-2012-1001MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) content pa | Nov 21, 2019 | 6.1 | 33 | NO | YES |
CVE-2011-2745MEDIUM upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote | Jul 27, 2011 | 6.5 | 30 | NO | YES |
CVE-2025-69768HIGH SQL Injection vulnerability in Chyrp v.2.5.2 and before allows a remote attacker to obtain sensitive information via the Admin.php component | Mar 16, 2026 | 7.5 | 26 | NO | NO |
CVE-2011-2743MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the action parameter to (1) the defau | Jul 19, 2011 | 4.3 | 24 | NO | YES |
CVE-2024-58285MEDIUM Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into post titles. Attackers can craft payloads in the t | Dec 10, 2025 | 5.4 | 20 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in admin/themes/default/pages/manage_users.twig in the Users Management feature in the admin component in Chyrp before 2.5.1 all | Dec 11, 2014 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chyrp.
Media articles that mention a CVE ID that affects a product developed by Chyrp — matched by CVE ID, not by vendor name.