|
Identifier
|
Related Record |
Severity
|
Date Published
|
Description | Versions Affected |
|---|---|---|---|---|---|
| CVE-2025-69768 | High | Mar 16, 2026 | SQL Injection vulnerability in Chyrp v.2.5.2 and before allows a remote attacker to obtain sensitive information via the Admin.php component |
2.5.2, 2.5.0, 2.1, 2.1.2, 2.0
|
|
| CVE-2024-58285 | Medium | Dec 10, 2025 | Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into post titles. Attacker more... |
2.5.2
|
|
| BDSA-2015-0356 | Critical | Jan 18, 2018 | The component is vulnerable to cross-site scripting (*XSS*) and cross-site request forgery (*CSRF*) attack via an HTTP GET request. An attacker can use more... |