CVE-2017-12905: Vebto Pixie - Image Editor

Critical severity, CVSS 10.0. EPSS: 2.6% chance of exploitation in the next 30 days.

Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.

Affected products

  • Vebto Pixie - Image Editor: version 1.4 only; version 1.7 only

Published 2017-09-25. Last modified 2026-06-17.