CLTPHP Content Management System是中国CLTPHP公司的一个内容管理系统。 CLTPHP Content Management System 3.0版本存在SQL注入漏洞,该漏洞源于对文件/home/search.html中参数keyword的错误操作,可能导致SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | CLTPHP | 3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-12286 | 7.0 HIGH | VeePN AVService avservice.exe unquoted search path |
| CVE-2025-12268 | 6.3 MEDIUM | LearnHouse Course Thumbnail courses unrestricted upload |
| CVE-2025-12204 | 5.3 MEDIUM | Kamailio Configuration File rvalue.c rve_destroy heap-based overflow |
| CVE-2025-12205 | 5.3 MEDIUM | Kamailio Configuration File cfg.lex sr_push_yy_state use after free |
| CVE-2025-12245 | 5.3 MEDIUM | chatwoot Widget IFrameHelper.js initPostMessageCommunication origin validation |
| CVE-2025-12310 | 5.3 MEDIUM | VirtFusion Email Change _settings excessive authentication |
| CVE-2025-12250 | 4.7 MEDIUM | OpenWGA TMLScript API WGA.File path traversal |
| CVE-2025-12246 | 4.3 MEDIUM | chatwoot Admin IframeLoader.vue cross site scripting |
| CVE-2025-12270 | 4.3 MEDIUM | LearnHouse Student Assignment Submission sub_file resource injection |
| CVE-2025-12276 | 4.3 MEDIUM | LearnHouse Image information disclosure |
| CVE-2025-12264 | 3.5 LOW | Wisencode Create Support Ticket create cross site scripting |
| CVE-2025-12269 | 3.5 LOW | LearnHouse Account Setting previews cross site scripting |
| CVE-2025-12251 | 3.5 LOW | OpenWGA Admin UI cross site scripting |
| CVE-2025-12207 | 3.3 LOW | Kamailio Grammar Rule cfg.y yyerror_at null pointer dereference |
| CVE-2025-12206 | 3.3 LOW | Kamailio rvalue.c rve_is_constant null pointer dereference |
| CVE-2025-61385 | pg8000 安全漏洞 | |
| CVE-2025-61099 | FRRouting FRR 安全漏洞 | |
| CVE-2025-61100 | FRRouting 安全漏洞 | |
| CVE-2025-61102 | FRRouting FRR 安全漏洞 | |
| CVE-2025-54965 | BAE Systems SOCET GXP 安全漏洞 |
Showing top 20 of 45 CVEs. View all on vendor page → →
No comments yet