tianti_project CVE 脆弱性と CVE 一覧(10)

製品(CPE): — CVE 件数: 10

tianti_project 脆弱性概要

tianti_project 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

過去の問題は主に vendor risk cross-site scripting and vendor risk csrf などに関し、一部は vendor impact session compromise を招き、vendor surface software deployment and vendor surface production workloads 関連の場面に影響します。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 110 / 10 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-9795 A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. [email protected] 2.1 0.21% 2025-09-01 2026-06-17
CVE-2025-8807 A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects unknown code of the file /tianti-module-admin/user/ajax/save. The manipulation leads to missing authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 2.1 0.28% 2025-08-10 2026-06-17
CVE-2025-27910 tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request. [email protected] 8.0 0.21% 2025-03-10 2026-06-17
CVE-2025-25908 A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the coverImageURL parameter at /article/ajax/save. [email protected] 5.4 0.25% 2025-03-10 2026-06-17
CVE-2025-25907 tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request. [email protected] 8.8 0.21% 2025-03-10 2026-06-17
CVE-2018-19110 The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/user/skin/list directly because controller\usercontroller.java maps a /skin/list request to the function skinList, and lacks an authorization check. [email protected] 6.5 1.22% 2018-11-08 2026-06-16
CVE-2018-19109 tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/cms/column/list directly to read the column list page or edit a column. [email protected] 8.8 1.77% 2018-11-08 2026-06-16
CVE-2018-19091 tianti 2.3 has reflected XSS in the user management module via the tianti-module-admin/user/list userName parameter. [email protected] 5.4 0.67% 2018-11-07 2026-06-16
CVE-2018-19090 tianti 2.3 has stored XSS in the article management module via an article title. [email protected] 5.4 0.67% 2018-11-07 2026-06-16
CVE-2018-19089 tianti 2.3 has stored XSS in the userlist module via the tianti-module-admin/user/ajax/save_role name parameter, which is mishandled in tianti-module-admin\src\main\webapp\WEB-INF\views\user\user_list.jsp. [email protected] 5.4 0.67% 2018-11-07 2026-06-16
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence