← Vulnerability feed

Vulnerability record · CVE-2025-10106 · published 8 September 2025

CVE-2025-10106: Chancms injection vulnerability

CChancms · Chancms

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

2.1 CVSS 4.0 Low EPSS 0.38% · top 70.6% CWE-74 · InjectionCWE-89 · SQL injection
2.1CVSS 4.0 base score, v2 6.5
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/chujianxin0101/vuln/issues/9 ExploitThird Party Advisory
https://vuldb.com/?ctiid.323073 Permissions RequiredVDB Entry
https://vuldb.com/?id.323073 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.645354 Third Party AdvisoryVDB Entry
https://github.com/chujianxin0101/vuln/issues/9 ExploitThird Party Advisory

Track CVE-2025-10106 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-65602Chancms code injection vulnerabilityA template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST…EPSS 0.54%2.1CVE-2025-11905Chancms injection vulnerabilityA vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\control…EPSS 0.82%2.1CVE-2025-11904Chancms injection vulnerabilityA vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation …EPSS 0.63%2.1CVE-2025-11903Chancms injection vulnerabilityA flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing a…EPSS 0.63%2.1CVE-2025-11902Chancms injection vulnerabilityA vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findField of the file /cms/article/f…EPSS 0.63%2.1CVE-2025-10211Chancms server-side request forgery (ssrf) vulnerabilityA security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/col…EPSS 0.71%2.1CVE-2025-10210Chancms injection vulnerabilityA weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Execu…EPSS 1.3%2.1CVE-2025-10110Chancms injection vulnerabilityA vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%2…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2025-10106), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.