Chyrplite develops a lightweight content management system, Chyrp Lite, with a vulnerability profile centered on web-application input handling and file management. The recurring weakness classes—authorization bypass through user-controlled keys, path traversal, unrestricted file uploads, and improper control of dynamically-identified variables—reflect common risks in user-facing CMS platforms where file operations and access control intersect. Current vulnerability counts, severity, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chyrplite over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35174HIGH Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user wit | Apr 6, 2026 | 7.2 | 26 | NO | NO |
CVE-2026-35173MEDIUM Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post model that allows authenticated users with post editing per | Apr 6, 2026 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chyrplite.
Media articles that mention a CVE ID that affects a product developed by Chyrplite — matched by CVE ID, not by vendor name.