Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityinternet-facing-service-vulnerabilitywidely-deployed-product-advisoryendpoint-software-vulnerability

Multiple Unrelated Critical Vulnerabilities Disclosed in October 2025

Updated 3mo agoFirst seen Oct 20, 202512 sources

A series of critical and high-severity vulnerabilities affecting a diverse set of software products were publicly disclosed in October 2025. Epsilon RH by Grupo Castilla was found to have a SQL injection vulnerability (CVE-2025-41028) that allows attackers to manipulate the database by sending crafted POST requests to the 'sEstadoUsr' parameter in the '/epsilonnetws/WSAvisos.asmx' endpoint. Lanscope Endpoint Manager (CVE-2025-61932) was reported to have an improper origin verification flaw, enabling attackers to execute arbitrary code via specially crafted packets, though remote exploitation is not possible. Galaxy Software Services Vitals ESP Forum Module (CVE-2025-31342) was discovered to allow remote authenticated users to upload dangerous files, leading to arbitrary command execution. Fsas Technologies Inc.'s ETERNUS SF (CVE-2025-62577) contains incorrect default permissions, allowing low-privileged users to obtain database credentials and potentially escalate privileges to execute OS commands as an administrator. Excellent Infotek's Document Management System (CVE-2025-11948) is vulnerable to unauthenticated arbitrary file upload, enabling attackers to deploy web shells and execute code on the server. Vvveb CMS up to version 1.0.5 is susceptible to authenticated code injection via its Code Editor, allowing attackers to modify files and achieve remote code execution. The Theme Editor plugin for WordPress (CVE-2025-9890) is vulnerable to cross-site request forgery, which can be exploited to achieve remote code execution if an administrator is tricked into clicking a malicious link. The PPOM plugin for WooCommerce (CVE-2025-11391) allows unauthenticated arbitrary file uploads, posing a severe risk to affected e-commerce sites. The Appointments plugin for WordPress (CVE-2017-20206) and the Flickr Gallery plugin (CVE-2017-20207) both suffer from unauthenticated PHP object injection vulnerabilities, which have been actively exploited to create backdoors using the WP_Theme() class. RegistrationMagic (CVE-2017-20208) is also affected by a PHP object injection flaw, allowing attackers to fetch and install remote files. Finally, BLU-IC2 and BLU-IC4 devices (CVE-2025-11925) have an API that returns an incorrect Content-Type header, potentially enabling HTML/JavaScript injection in responses. Each of these vulnerabilities presents a significant risk, with several allowing remote code execution, privilege escalation, or the installation of persistent backdoors. The affected products span web applications, content management systems, endpoint management tools, and specialized enterprise software. Security teams are advised to review the specific advisories, apply patches or mitigations where available, and monitor for signs of exploitation, as several vulnerabilities have been reported as actively exploited in the wild. The diversity and severity of these disclosures underscore the ongoing need for rigorous vulnerability management and timely response to public advisories.

Share:
Multiple Unrelated Critical Vulnerabilities Disclosed in October 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Oct 20, 20258mo ago

CVE-2025-41028 SQL injection in Epsilon RH is published

A critical unauthenticated SQL injection vulnerability, CVE-2025-41028, was published for Epsilon RH. The flaw affects the `/epsilonnetws/WSAvisos.asmx` endpoint via the `sEstadoUsr` parameter and could let remote attackers read or modify database records.

Oct 19, 20258mo ago

Metasploit pull request adds Vvveb CMS CVE-2025-8518 exploit module

A Metasploit Framework pull request was opened to add an authenticated remote code execution module for Vvveb CMS tied to CVE-2025-8518. This represents public technical enablement for exploitation of the vulnerability.

Oct 18, 20258mo ago

Theme Editor WordPress plugin RCE-related CSRF flaw published

CVE-2025-9890 was published for the WordPress Theme Editor plugin through version 3.0. The flaw stems from missing or incorrect nonce validation on the `theme_editor_theme` page and could allow remote code execution if an administrator is tricked into performing a malicious request.

Appointments WordPress plugin flaw is actively exploited in the wild

A critical unauthenticated PHP object injection vulnerability affecting the WordPress Appointments plugin through version 2.2.1 was reported as being actively exploited. Attackers were said to abuse deserialization of the `wpmudev_appointments` cookie and leverage the `WP_Theme()` class to create backdoors.

Oct 17, 20258mo ago

CVE-2025-11925 disclosed for BLU-IC2 and BLU-IC4 API content-type issue

A critical vulnerability, CVE-2025-11925, was published for BLU-IC2 and BLU-IC4 through version 1.19.5. The issue involves API endpoints returning `text/html` instead of `application/json`, creating a risk of HTML or JavaScript injection in responses, with remediation guidance to correct response headers.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Affected products
4 linked
Epsilon RhBlu-Ic2Blu-Ic4Wordpress
Organizations
8 linked
Grupo CastillaWordfenceThemeeditorVvvebAzure-AccessMotexLanscope Endpoint ManagerJapan Computer Emergency Response Team Coordination Center
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.