CVE-2025-0987: Cb Project Ltd. Co Cvland

Critical severity, CVSS 9.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection. This issue affects CVLand: from 2.1.0 through 20251103. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Published 2025-11-03. Last modified 2026-06-17.