📦 Tianti

by Tianti Project

🔍 What is Tianti?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-27910

HIGH CVSS 8.0 Mar 10, 2025

This CSRF vulnerability in tianti v2.3 allows attackers to trick authenticated users into performing unintended actions via malicious requests to /user/ajax/upd/status. Any tianti v2.3 installation wi...

CVE-2025-25907

HIGH CVSS 8.8 Mar 10, 2025

CVE-2025-25907 is a Cross-Site Request Forgery vulnerability in tianti v2.3 that allows attackers to trick authenticated users into performing unintended actions via crafted requests to /user/ajax/sav...

CVE-2025-8807

MEDIUM CVSS 6.3 Aug 10, 2025

This critical vulnerability in xujeff tianti (夊梯) up to version 2.3 allows remote attackers to bypass authorization controls on the /tianti-module-admin/user/ajax/save endpoint. Attackers can pote...

CVE-2025-25908

MEDIUM CVSS 5.4 Mar 10, 2025

A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to inject malicious scripts into the coverImageURL parameter when saving articles. This affects all users of tianti v2...