Products: 1
    Vulnerabilities: 8
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    6
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-69768

    SQL Injection in Chyrp Admin Component Allows Remote Data Retrieval

    Last Modified: Mar 23, 2026
    Published: Mar 16, 2026

    CVE-2024-58285

    Chyrp 2.5.2 Stored Cross-Site Scripting Vulnerability via Post Title

    Last Modified: Mar 05, 2026
    Published: Dec 10, 2025

    CVE-2012-1001

    Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) content parameter to includes/ajax.php or (2) body parameter to includes/error.php.

    Last Modified: Nov 21, 2024
    Published: Nov 21, 2019

    CVE-2014-7264

    Multiple cross-site scripting (XSS) vulnerabilities in admin/themes/default/pages/manage_users.twig in the Users Management feature in the admin component in Chyrp before 2.5.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) user.email or (2) user.website field in a user registration.

    Last Modified: Apr 12, 2025
    Published: Dec 11, 2014

    CVE-2011-2745

    upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.

    Last Modified: Apr 11, 2025
    Published: Jul 27, 2011
    Items Per Page