← Vulnerability feed

Vulnerability record · CVE-2025-10110 · published 8 September 2025

CVE-2025-10110: Chancms injection vulnerability

CChancms · Chancms

A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

2.1 CVSS 4.0 Low EPSS 0.34% · top 75.2% CWE-74 · InjectionCWE-89 · SQL injection
2.1CVSS 4.0 base score, v2 6.5
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/chujianxin0101/vuln/issues/10 ExploitIssue Tracking
https://vuldb.com/?ctiid.323076 Permissions RequiredVDB Entry
https://vuldb.com/?id.323076 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.645383 Third Party AdvisoryVDB Entry
https://github.com/chujianxin0101/vuln/issues/10 ExploitIssue Tracking

Track CVE-2025-10110 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-65602Chancms code injection vulnerabilityA template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST…EPSS 0.54%2.1CVE-2025-11905Chancms injection vulnerabilityA vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\control…EPSS 0.82%2.1CVE-2025-11904Chancms injection vulnerabilityA vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation …EPSS 0.63%2.1CVE-2025-11903Chancms injection vulnerabilityA flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing a…EPSS 0.63%2.1CVE-2025-11902Chancms injection vulnerabilityA vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findField of the file /cms/article/f…EPSS 0.63%2.1CVE-2025-10211Chancms server-side request forgery (ssrf) vulnerabilityA security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/col…EPSS 0.71%2.1CVE-2025-10210Chancms injection vulnerabilityA weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Execu…EPSS 1.3%2.1CVE-2025-10106Chancms injection vulnerabilityA vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation o…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2025-10110), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.