PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Web Vulnerabilities·Updated Dec 1, 2025

ChanCMS <= 3.3.0 - SQL Injection

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
5.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.
Description

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
ChanCMSby yanyutao0402
3.0
Updated Sep 18, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

ChanCMS <= 3.3.0 - SQL Injection CVE-2025-10210 Scanner | S4E