CVE-2025-71250Disclosure

LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-19: 3Technical Details · 2026-02-19: 302-19
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-71250 Insecure Deserialization Vulnerability in SPIP before 4.4.9 Leading to Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-71250

    Post summary

    A newly disclosed vulnerability (CVE-2025-71250) in SPIP <4.4.9 permits insecure deserialization that can lead to code execution, with no mention of PoC, exploitation, or remediation.

    0000148
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-71250 - High SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious s... https://www.thehackerwire.com/vulnerability/CVE-2025-71250/ https://t.co/YapSUeKbmn

    Post summary

    The post announces CVE‑2025‑71250, outlining insecure deserialization flaws in SPIP versions prior to 4.4.9 via the table_valeur filter and DATA iterator, but it provides no PoC, exploit, active usage, patch, or mitigation details.

    0000044
    112 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-71250** pertains to an **Insecure Deserialization** flaw present in **SPIP** versions prior to **4.4.9**. The vulnerability resides specifically within the handling of serialized data in the **public area** through the **table_valeur filter** and the **DATA iterator**. These components accept serialized data, which, if maliciously crafted, can lead to **arbitrary object instantiation** and potentially **remote code execution (RCE)**. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #DDoS https://cvetodo.com/cve/CVE-2025-71250

    Post summary

    The post announces a new insecure deserialization flaw in SPIP versions prior to 4.4.9 that could lead to remote code execution, but provides no proof of exploitation or mitigation details.

    0000036
    20 followersView on X

Explore more