← Back to browse · API

CVE-2025-63689

Severity
CRITICAL
CVSS
10.0
EPSS
0.00858
Risk score
40.3
CISA KEV
No
PoC
No
Published
2025-11-07
Modified
2026-01-27
First seen
2026-08-07
Aliases
EUVD-2025-38273, GHSA-3XHW-HF92-CGV2
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-38273

Description

Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) allows a remote attacker to execute arbitrary code via the orderby parameter

References