Tianti Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 11
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    8
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-9795

    xujeff tianti 天梯 UploadController.java ajaxUploadFile unrestricted upload

    Last Modified: Sep 04, 2025
    Published: Sep 01, 2025

    CVE-2025-8808

    xujeff tianti 天梯 com.jeff.tianti.controller save exportOrder csv injection

    Last Modified: Apr 15, 2026
    Published: Aug 10, 2025

    CVE-2025-8807

    xujeff tianti 天梯 save authorization

    Last Modified: Sep 16, 2025
    Published: Aug 10, 2025

    CVE-2025-25908

    A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the coverImageURL parameter at /article/ajax/save.

    Last Modified: Jun 23, 2025
    Published: Mar 10, 2025

    CVE-2025-27910

    tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request.

    Last Modified: May 21, 2025
    Published: Mar 10, 2025
    Items Per Page
    Tianti_Project Vulnerabilities & Security CVEs | CVE-DB