Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

9001 — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting 9001. AI-powered Chinese analysis, POCs, and references for each vulnerability.

9001 is a widely deployed web application framework primarily used for building enterprise-level content management systems and e-commerce platforms. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, contributing to its 11 recorded CVEs. The framework's modular architecture, while flexible, has introduced security challenges through third-party extensions and insufficient input validation. Notable incidents include several high-profile breaches where attackers leveraged RCE vulnerabilities to compromise servers and exfiltrate sensitive data, highlighting ongoing concerns about secure coding practices and timely patch management within its ecosystem.

Top products by 9001: copyparty
CVE ID Title CVSS Severity Published
CVE-2026-93353 copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers — copyparty CWE-59 3.1 Low 2026-09-24
CVE-2026-70657 Copyparty: file/dirkey confusion — copyparty CWE-863 4.3 Medium 2026-08-18
CVE-2026-32109 Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html` — copyparty CWE-79 3.7 Low 2026-03-11
CVE-2026-32108 Copyparty ftp/sftp: Sharing a single file did not fully restrict source-folder access — copyparty CWE-863 7.5AI High AI 2026-03-11
CVE-2026-30974 Copyparty volflag `nohtml` did not block javascript in svg files — copyparty CWE-79 4.6 Medium 2026-03-10
CVE-2026-27948 Copyparty vulnerable to eflected cross-site scripting via setck parameter — copyparty CWE-79 5.4 Medium 2026-02-26
CVE-2025-58753 copyparty: Sharing a single file does not fully restrict access to other files in source folder — copyparty CWE-862 5.3AI Medium AI 2025-09-09
CVE-2025-54796 Copyparty is vulnerable to Regex Denial of Service (ReDoS) attacks through "Recent Uploads" page — copyparty CWE-400 7.5 High 2025-08-01
CVE-2025-54589 copyparty Reflected XSS via Filter Parameter — copyparty CWE-79 6.3 Medium 2025-07-31
CVE-2025-54423 copyparty has a DOM-Based XSS vulnerability when displaying multimedia metadata — copyparty CWE-79 5.4 Medium 2025-07-28
CVE-2025-27145 copyparty renders unsanitized filenames as HTML when user uploads empty files — copyparty CWE-83 3.6 Low 2025-02-25
CVE-2023-38501 copyparty vulnerable to reflected cross-site scripting via k304 parameter — copyparty CWE-79 6.3 Medium 2023-07-25
CVE-2023-37474 Path traversal in copyparty — copyparty CWE-22 9.8 - 2023-07-14

This page lists every published CVE security advisory associated with 9001. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.