CVE-2025-69770Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-13); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-13: 4Mentions · 2026-02-18: 1Technical Details · 2026-02-13: 4Technical Details · 2026-02-18: 102-1302-18
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-134
Disclosure4
2026-02-181
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-69770 (CVSS:10.0, CRITICAL) is Awaiting Analysis. A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execu..https://nvd.nist.gov/vuln/detail/CVE-2025-69770 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2025‑69770, a critical zip slip vulnerability in MojoPortal CMS, providing technical details but no proof‑of‑concept, exploit, or patch information.

    0000046
    171 followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Disclosure

    CVE-2025-69770 i MojoPortal CMS möjliggör angrepp via zip slip-sårbarhet. Angripare kan exekvera godtyckliga kommandon genom att ladda upp skadliga zip-filer, vilket kan leda till allvarliga konsekvenser. Skydda ditt system nu! #säkerhet #cybersäkerhet #CVE

    Post summary

    The tweet announces a zip slip vulnerability in MojoPortal CMS (CVE-2025-69770) that permits arbitrary command execution via malicious zip uploads.

    0000037
    7 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-69770: CRITICAL] A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.#cve,CVE-2025-69770,#cybersecurity https://cvefind.com/CVE-2025-69770

    Post summary

    A critical zip slip vulnerability (CVE‑2025‑69770) in MojoPortal CMS v2.9.0.1 has been disclosed, allowing arbitrary command execution through crafted zip uploads.

    0000050
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-69770 - Critical A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file. https://www.thehackerwire.com/vulnerability/CVE-2025-69770/ https://t.co/rEB3TfYziZ

    Post summary

    The post announces CVE-2025-69770, detailing a zip slip vulnerability in MojoPortal CMS that permits arbitrary command execution through a crafted zip upload, with no mention of PoC, exploits, or patches.

    0000050
    112 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-69770 Zip Slip Vulnerability in MojoPortal CMS 2.9.0.1 Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69770

    Post summary

    CVE-2025-69770 is a Zip Slip vulnerability in MojoPortal CMS 2.9.0.1 that allows remote code execution, with a link to additional details.

    0000031
    4.0K followersView on X

Explore more