PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 1, 2025

ChanCMS <= 3.3.0 - Server-Side Request Forgery

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
5.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.
Description

A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulation of the argument taskUrl leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
ChanCMSby yanyutao0402
3.3.0
Updated Sep 18, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

ChanCMS <= 3.3.0 - Server-Side Request Forgery CVE-2025-10211 Scanner | S4E