Tianti Project maintains a niche web application platform whose vulnerability profile centers on application-layer and access-control weaknesses endemic to web frameworks. The recurring issues—cross-site scripting, cross-site request forgery, missing authorization, and improper access control—reflect the web-facing context and session-management demands of the single main product. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tianti Project over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8807HIGH A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects unknown code of the file /tianti-module-admin/user/ajax/save. | Aug 10, 2025 | 8.8 | 28 | NO | NO |
CVE-2018-19109HIGH tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/cms/column/list directly to read the column list page or edi | Nov 8, 2018 | 8.8 | 27 | NO | NO |
CVE-2025-25907HIGH tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arbitrary operations via | Mar 10, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-27910HIGH tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operatio | Mar 10, 2025 | 8.0 | 21 | NO | NO |
CVE-2018-19110MEDIUM The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/user/skin/list directly becau | Nov 8, 2018 | 6.5 | 21 | NO | NO |
CVE-2018-19091MEDIUM tianti 2.3 has reflected XSS in the user management module via the tianti-module-admin/user/list userName parameter. | Nov 7, 2018 | 5.4 | 20 | NO | NO |
CVE-2018-19090MEDIUM tianti 2.3 has stored XSS in the article management module via an article title. | Nov 7, 2018 | 5.4 | 20 | NO | NO |
CVE-2018-19089MEDIUM tianti 2.3 has stored XSS in the userlist module via the tianti-module-admin/user/ajax/save_role name parameter, which is mishandled in tianti-module-admin\src\main\webapp\WEB-INF\ | Nov 7, 2018 | 5.4 | 20 | NO | NO |
CVE-2025-9795MEDIUM A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadControl | Sep 1, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-25908MEDIUM A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the coverImageURL pa | Mar 10, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tianti Project.
Media articles that mention a CVE ID that affects a product developed by Tianti Project — matched by CVE ID, not by vendor name.