CVE-2019-25335Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PRO-7070 Hazır Profesyonel Web Sitesi version 1.0 contains an authentication bypass vulnerability in the administration panel login page. Attackers can bypass authentication by using '=' 'or' as both username and password to gain unauthorized access to the administrative interface.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-13: 2Technical Details · 2026-02-13: 102-13
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets6 URLs
Full discourse2 posts
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 13, 2026 1. Critical WPvivid Backup Flaw (CVSS 9.8) Exposes 800K WordPress Sites A critical vulnerability (CVE-2026-1357) in the WPvivid Backup plugin affects over 800,000 WordPress sites, potentially exposing sensitive backup data. This flaw poses a significant risk of data compromise and site integrity loss if exploited. Sources: Bleepingcomputer, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Intel471, Malwarebytes, Mandiant, Proofpoint, Securityweek, Therecord https://securityonline.info/null-byte-nightmare-critical-wpvivid-backup-flaw-cvss-9-8-exposes-800k-wordpress-sites/ 2. Critical SandboxJS Vulnerability (CVE-2026-25881) Enables Host Takeover A critical flaw in SandboxJS allows attackers to escape the sandbox environment and execute malicious code on the host system. This vulnerability poses a severe risk to applications relying on SandboxJS for secure JavaScript execution. Sources: Cvefeed, Microsoft https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/ 3. Multiple High and Critical Vulnerabilities Including Authentication Bypass, Buffer Overflows, and Path Traversal A series of critical and high-severity vulnerabilities have been disclosed affecting various software products including PRO-7070, OwnCloud, SpotAuditor, and others. These vulnerabilities enable attackers to bypass authentication, execute arbitrary code via buffer overflows and stack overflows, perform path traversal to access sensitive files, and disclose usernames, posing significant risks to affected systems. Immediate patching and mitigation are recommended to prevent unauthorized access and potential system compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2019-25335 4. Multiple Critical Vulnerabilities in CIPPlanner CIPAce Allow Privilege Escalation and Arbitrary File Access CIPPlanner CIPAce versions before 9.17 contain multiple severe vulnerabilities including account privilege escalation, unauthorized file download, and arbitrary file upload of executable files. These flaws enable low-privileged authenticated users to escalate privileges, access unauthorized files, and potentially execute malicious code, posing significant security risks. Sources: Cvefeed, Feedburner, Securityaffairs https://cvefeed.io/vuln/detail/CVE-2024-50619 5. Critical Authentication Bypass Vulnerabilities Found in ZLAN5143D Devices Two critical vulnerabilities (CVE-2026-25084 and CVE-2026-24789) affect ZLAN5143D devices, allowing attackers to bypass authentication and remotely change device passwords via unprotected internal URLs and API endpoints. These flaws expose devices to unauthorized access and control, posing significant security risks. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-25084 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article announces several newly disclosed high‑severity CVEs affecting WordPress, SandboxJS, and other software, detailing their impact and recommending patching, without providing PoC or exploit details.

    0001056
    54 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2019-25335 - Websitem - 7070 Hazır Profesyonel Web Sitesi - https://www.redpacketsecurity.com/cve-alert-cve-2019-25335-websitem-7070-haz-r-profesyonel-web-sitesi/ #OSINT #ThreatIntel #CyberSecurity #cve-2019-25335 #websitem #7070-haz-r-profesyonel-web-sitesi

    Post summary

    The tweet is a brief CVE alert that references a link for more information but provides no further details.

    0000062
    3.5K followersView on X

Explore more