Yandaozi's vulnerability profile centers on a narrowly scoped product line, specifically the PPress application, with a durable signal characterized by web-application and access-control weaknesses including improper authentication, code injection, cross-site scripting, privilege management flaws, and session fixation. These weakness classes reflect the input-handling and session-management demands of web-facing applications; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yandaozi over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54815HIGH Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes. | Sep 19, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-52159HIGH Hardcoded credentials in default configuration of PPress 0.0.9. | Sep 19, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-54761HIGH An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie. | Sep 19, 2025 | 8.0 | 25 | NO | NO |
CVE-2025-25973MEDIUM A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted script to th | Feb 20, 2025 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yandaozi.
Media articles that mention a CVE ID that affects a product developed by Yandaozi — matched by CVE ID, not by vendor name.