CVE-2025-69770
Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.
A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.
Published 2026-02-13. Last modified 2026-06-17.