References https://nvd.nist.gov/vuln/detail/CVE-2025-8266 https://github.com/advisories/GHSA-pg2f-hfwm-m7g5 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-8266.yaml https://vulners.com/cve/CVE-2025-8266 https://vuldb.com/?id.317857 https://access.redhat.com/security/cve/cve-2025-8266 https://avd.aliyun.com/high-risk/list?page=2 https://github.com/Threekiii/CVE https://blog.csdn.net/m0_50125527/article/details/150412965 https://pentest-tools.com/vulnerabilities-exploits/chancms-31-remote-code-execution_28843
Related VulnerabilitiesChanCMS SQL注入漏洞(CVE-2025-10210)PoCCVE-2025-8266: ChanCMS <= 3.1. - Remote Code ExecutionPoCCVE-2025-10210: ChanCMS <= 3.3.0 - SQL InjectionPoCCVE-2025-10211: ChanCMS <= 3.3.0 - Server-Side Request Forgery(CVE-2025-10211)ChanCMS 3.3.0 CollectController SSRF漏洞(CVE-2025-10210) ChanCMS Search功能SQL注入漏洞ChanCMS系统/api/sysUser/login存在默认弱口令