---
id: CVE-2025-11022
title: "Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery.\_\n\nThis \n\nCSRF vulnerability resulting in Command Injection has been identified.\n\n\n\n\n\nThis issue affects Panilux: before v.0.10…"
summary: "Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery.\_\n\nThis \n\nCSRF vulnerability resulting in Command Injection has been identified.\n\n\n\n\n\nThis issue affects Panilux: before v.0.10…"
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-352
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11022'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0433'
    label: iletisim@usom.gov.tr
  - url: 'https://www.usom.gov.tr/bildirim/tr-25-0433'
    label: iletisim@usom.gov.tr
tags:
  - nvd
epss: 0.00553
epssPercentile: 0.44347
ingestedAt: '2026-10-07T20:46:46.782Z'
---

## Overview

Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery. 

This 

CSRF vulnerability resulting in Command Injection has been identified.





This issue affects Panilux: before v.0.10.0. NOTE: The vendor was contacted and responded that they deny ownership of the mentioned product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
