Vulnerabilities
Vulnerable Software
Chyrp:  >> Chyrp  >> 2.5.2  Security Vulnerabilities
SQL Injection vulnerability in Chyrp v.2.5.2 and before allows a remote attacker to obtain sensitive information via the Admin.php component
CVSS Score
7.5
EPSS Score
0.0
Published
2026-03-16
Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into post titles. Attackers can craft payloads in the title field that will execute when the post is viewed by other users, potentially stealing session cookies or performing client-side attacks.
CVSS Score
5.3
EPSS Score
0.001
Published
2025-12-10
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) content parameter to includes/ajax.php or (2) body parameter to includes/error.php.
CVSS Score
6.1
EPSS Score
0.192
Published
2019-11-21


Contact Us

Shodan ® - All rights reserved