A vulnerability was found in Typecho up to 1.3.0. This vulnerability affects the function Service::sendPingHandle of the file var/Widget/Service.php of the component Ping Back Service Endpoint. The manipulation of the argument X-Pingback/link results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Project Subscriptions

Vendors Products
Typecho Subscribe
Typecho Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 26 Apr 2026 07:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Typecho up to 1.3.0. This vulnerability affects the function Service::sendPingHandle of the file var/Widget/Service.php of the component Ping Back Service Endpoint. The manipulation of the argument X-Pingback/link results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Typecho Ping Back Service Endpoint Service.php sendPingHandle server-side request forgery
First Time appeared Typecho
Typecho typecho
Weaknesses CWE-918
CPEs cpe:2.3:a:typecho:typecho:*:*:*:*:*:*:*:*
Vendors & Products Typecho
Typecho typecho
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-26T07:00:17.124Z

Reserved: 2026-04-25T14:11:33.523Z

Link: CVE-2026-7025

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-26T08:16:00.227

Modified: 2026-04-26T08:16:00.227

Link: CVE-2026-7025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses