yanyutao0402 ChanCMS = 3.3.0 contains a SQL injection caused by manipulation of the \"key\" argument in app/modules/api/service/Api.js Search function, letting remote attackers execute arbitrary SQL commands, exploit requires crafted request.
id: CVE-2025-10210
info:
name: ChanCMS <= 3.3.0 - SQL Injection
author: Yu_Bao
severity: medi
...