CVE
CVE-2025-10210
2.1
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.
Description
A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Attack Vector
Network
Privileges Req.
Low
User Interaction
None
chancms
Updated Sep 18, 2026View on NVD →
This CVE is in S4E's catalog, but no public scanner is mapped to it yet.
CVE history: chancms
Predict next CVE date with AIMonitor this CVE on your assets
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →