yandaozi ppress CVE Vulnerabilities (4)

CVEs: 4 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting yandaozi ppress (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-54815 Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes. [email protected] 8.8 0.56% 2025-09-19 2026-06-17
CVE-2025-54761 An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie. [email protected] 8.0 0.30% 2025-09-19 2026-06-17
CVE-2025-52159 Hardcoded credentials in default configuration of PPress 0.0.9. [email protected] 8.8 0.38% 2025-09-19 2026-06-17
CVE-2025-25973 A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted script to the article.title, article.category, and article.tags parameters. [email protected] 6.5 0.50% 2025-02-20 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence