CVE-2026-7025General

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Typecho up to 1.3.0. This vulnerability affects the function Service::sendPingHandle of the file var/Widget/Service.php of the component Ping Back Service Endpoint. The manipulation of the argument X-Pingback/link results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-26: 3Technical Details · 2026-04-26: 104-26
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-7025 A vulnerability was found in Typecho up to 1.3.0. This vulnerability affects the function Service::sendPingHandle of the file var/Widget/Service.php of the component Pi… https://www.cve.org/CVERecord?id=CVE-2026-7025

    Post summary

    The snippet identifies CVE-2026-7025 and its affected file, but offers no further details or actionable information.

    00000121
    57.3K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7025 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7025 #CVE-2026-7025 #CVE #High #CyberSecurity #InfoSec https://t.co/avYAaUf1hs

    Post summary

    The tweet reports a newly disclosed CVE-2026-7025 with a high severity score but offers no technical specifics, patch information, or evidence of exploitation.

    0000054
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7025 Server-Side Request Forgery in Typecho Up to 1.3.0 Ping Back Service https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7025

    Post summary

    A Server‑Side Request Forgery vulnerability (CVE-2026-7025) affecting Typecho's Ping Back Service up to version 1.3.0 is disclosed, with technical details provided but no exploitation evidence or patches announced.

    0000043
    4.0K followersView on X

Explore more