---
id: CVE-2025-10210
title: A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0
summary: >-
  A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted
  is the function Search of the file app/modules/api/service/Api.js. Executing
  manipulation of the argument key can lead to sql injection. The attack can be
  launc…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: chancms
product: chancms
affected:
  - chancms <= 3.3.0
published: '2025-09-10'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10210'
references:
  - url: 'https://github.com/August829/Yu/blob/main/58ead8e7e08bfb0e5.md'
    label: cna@vuldb.com
  - url: 'https://github.com/August829/Yu/blob/main/58ead8e7e08bfb0e5.md#poc'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.323483'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.323483'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.639777'
    label: cna@vuldb.com
tags:
  - nvd
  - exploit-available
epss: 0.01297
epssPercentile: 0.69161
exploits:
  nuclei:
    - CVE-2025-10210
  checkedAt: '2026-09-26T00:23:14.496Z'
exploitAvailable: true
ingestedAt: '2026-09-26T00:22:39.916Z'
---

## Overview

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `chancms <= 3.3.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
