CVE detail
CVE-2025-12616
A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertion of sensitive information into debugging code. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://vuldb.com/?submit.678649vuldb.com
No excerpt available.
Exploitvuldb.comNov 3, 2025, 4:15 AM - https://vuldb.com/?id.330910vuldb.com
No excerpt available.
Exploitvuldb.comNov 3, 2025, 4:15 AM - https://vuldb.com/?ctiid.330910vuldb.com
No excerpt available.
Exploitvuldb.comNov 3, 2025, 4:15 AM - https://phpgurukul.com/phpgurukul.com
No excerpt available.
Permissions Requiredphpgurukul.comNov 3, 2025, 4:15 AM No excerpt available.
Exploitgithub.comNov 3, 2025, 4:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- NishantKumar-CSE/News-Portal-Python-Django-ProjectHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 24, 2026, 6:20 AM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-40173CVSS 9.4 · Critical
Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endp…
- CVE-2019-3781CVSS 8.8 · High
Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious use…
- CVE-2018-1191CVSS 8.8 · High
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and…
- CVE-2026-54785CVSS 6.2 · Medium
gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any…
- CVE-2026-45377CVSS 6.5 · Medium
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the re…
- CVE-2026-55824CVSS 2.6 · Low
Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to preve…