Mindskip's vulnerability profile centers on a narrowly scoped product line around its XZS-MySQL application, where disclosures cluster across web-application and session-management weaknesses including cross-site scripting, cross-site request forgery, code injection, and insufficient session expiration. The recurring pattern reflects typical risks in database-facing web applications where input handling and access control are central; vulnerabilities affecting this vendor skew toward serious outcomes. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mindskip over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-29401CRITICAL xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything. | Mar 26, 2024 | 9.8 | 24 | NO | NO |
CVE-2025-1083MEDIUM A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler. | Feb 6, 2025 | 6.8 | 20 | NO | NO |
CVE-2022-41431MEDIUM xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. This vulnerability allows attackers to execute arbitrary web | Oct 17, 2022 | 5.4 | 20 | NO | NO |
CVE-2021-46086HIGH xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functio | Jan 25, 2022 | 7.5 | 19 | NO | NO |
CVE-2025-1082MEDIUM A vulnerability classified as problematic has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected is an unknown function of the file /api/admin/question/edit of the componen | Feb 6, 2025 | 5.4 | 17 | NO | NO |
CVE-2025-1084MEDIUM A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this issue is some unknown functionality. The manipulation l | Feb 7, 2025 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mindskip.
Media articles that mention a CVE ID that affects a product developed by Mindskip — matched by CVE ID, not by vendor name.