CVE-2025-11022: Personal Project Panilux

Critical severity, CVSS 9.6. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery.  This CSRF vulnerability resulting in Command Injection has been identified. This issue affects Panilux: before v.0.10.0. NOTE: The vendor was contacted and responded that they deny ownership of the mentioned product.

Affected products

Published 2025-12-09. Last modified 2026-10-07.