CVE-2025-54815: Yandaozi Ppress
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.
Affected products
- Yandaozi Ppress: version 0.0.9 only
Published 2025-09-19. Last modified 2026-06-17.