CVE-2025-10970Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc. Talentics allows Blind SQL Injection. This issue affects Talentics: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-20); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-20: 3Mentions · 2026-02-25: 1Technical Details · 2026-02-20: 3Technical Details · 2026-02-25: 102-2002-25
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-203
Disclosure3
2026-02-251
Disclosure1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-10970 (CVSS:9.8, CRITICAL) is Awaiting Analysis. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc..https://nvd.nist.gov/vuln/detail/CVE-2025-10970 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2025-10970, a critical SQL injection vulnerability in Kolay Software Inc., with a CVSS score of 9.8, but does not provide PoC, exploit, or patch details.

    0000038
    172 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-10970 SQL Injection in Kolay Software Talentics Through 20022026 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-10970

    Post summary

    The snippet announces a SQL Injection flaw in Kolay Software Talentics (versions 20022026), without discussing PoCs, exploits, patches, or live attacks.

    0000033
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-10970: CRITICAL] Critical SQL Injection vulnerability found in Kolay Software Inc. Talentics, allowing for Blind SQL Injection. Issue persists through version 20022026. Vendor unresponsive to discl...#cve,CVE-2025-10970,#cybersecurity https://cvefind.com/CVE-2025-10970

    Post summary

    The post discloses a critical blind SQL injection in Kolay Software Inc.’s Talentics product (v20022026), noting vendor unresponsiveness and no available patch or exploitation evidence.

    0000054
    578 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-10970 - Critical Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc. Talentics allows Blind SQL Injection.This issue affects Talentics... https://www.thehackerwire.com/vulnerability/CVE-2025-10970/ https://t.co/NOdvsVqOTs

    Post summary

    The tweet announces CVE-2025-10970 as a critical blind SQL injection flaw in Kolay Software's Talentics, providing basic technical details without any PoC, exploit, patch or active exploitation information.

    0000045
    112 followersView on X

Explore more