Xujiangfei's vulnerability footprint centers on a narrowly scoped administrative application, AdminTwo, where vulnerabilities skew toward serious outcomes and cluster around web-application and access-control weaknesses. The recurring exposure involves code injection, cross-site scripting, improper access control, and privilege-assignment flaws that are characteristic of administrative interfaces handling user input and session management. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xujiangfei over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3254CRITICAL A vulnerability was found in xujiangfei admintwo 1.0. It has been classified as critical. Affected is an unknown function of the file /resource/add. The manipulation of the argumen | Apr 4, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-3256HIGH A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/updateSet. The manipulat | Apr 4, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-3255HIGH A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /user/home. The ma | Apr 4, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-3253MEDIUM A vulnerability was found in xujiangfei admintwo 1.0 and classified as problematic. This issue affects some unknown processing of the file /ztree/insertTree. The manipulation of th | Apr 4, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-3252MEDIUM A vulnerability has been found in xujiangfei admintwo 1.0 and classified as problematic. This vulnerability affects unknown code of the file /resource/add. The manipulation of the | Apr 4, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-3251MEDIUM A vulnerability, which was classified as problematic, was found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet. The manipulation of the argume | Apr 4, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-3257MEDIUM A vulnerability classified as problematic has been found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet. The manipulation leads to cross-site | Apr 4, 2025 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xujiangfei.
Media articles that mention a CVE ID that affects a product developed by Xujiangfei — matched by CVE ID, not by vendor name.