VendorsYandaozippress0.0.9
Vulnerabilities

Yandaozi Ppress 0.0.9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-54815
Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.
Published 2025-09-19 · Analyzed
8.8EPSS 0.006
CVE-2025-52159
Hardcoded credentials in default configuration of PPress 0.0.9.
Published 2025-09-19 · Analyzed
8.8EPSS 0.004
CVE-2025-54761
An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.
Published 2025-09-19 · Analyzed
8.0EPSS 0.003
CVE-2025-25973
A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted script to the article.title, article.category, and article.tags parameters.
Published 2025-02-20 · Analyzed
6.5EPSS 0.005