CVE-2020-19962: Chaoji CMS Project Chaoji CMS

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts.

Affected products

Published 2021-10-14. Last modified 2026-06-17.