Hzmanyun develops an education and training system that has surfaced vulnerabilities concentrated in command injection, OS command injection, broader injection flaws, unrestricted file upload, and access-control weaknesses—patterns typical of web applications handling user input and file operations without sufficient sanitization. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hzmanyun over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1947CRITICAL A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3. This affects the function scorm of the file UploadImageController.java. The m | Mar 4, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-1946CRITICAL A vulnerability was found in hzmanyun Education and Training System 2.1. It has been rated as critical. Affected by this issue is the function exportPDF of the file /user/exportPDF | Mar 4, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-1676CRITICAL A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. Affected by this vulnerability is the function pdf2swf of the file /pdf2swf. The m | Feb 25, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-1555CRITICAL A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. The manipulation of the argumen | Feb 21, 2025 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hzmanyun.
Media articles that mention a CVE ID that affects a product developed by Hzmanyun — matched by CVE ID, not by vendor name.