CVE-2019-25441: Kostasmitroglou Thesystem

Critical severity, CVSS 9.8. EPSS: 8.5% chance of exploitation in the next 30 days.

thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the run_command endpoint. Attackers can send POST requests with shell commands in the command parameter to execute arbitrary code on the server without authentication.

Affected products

Published 2026-02-20. Last modified 2026-06-17.