Harry0703 maintains a narrowly scoped tool focused on financial applications, with vulnerabilities that skew strongly toward critical severity across a concentrated attack surface. The recurring exposure centers on the MoneyPrinterTurbo product and clusters around authentication and access-control weaknesses—including missing authentication enforcement, improper access controls, path traversal, and unrestricted file uploads—that are characteristic of web-facing financial software lacking defense-in-depth controls. Live exploitation activity, severity breakdown, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Harry0703 over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11607HIGH A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controllers/v1/music.py of the componen | Oct 11, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-7895CRITICAL A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of the file app/controllers/v1/vid | Jul 20, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-10472HIGH A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download_video/stream_video of the file app/controllers/v1/video.py | Sep 15, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-7897CRITICAL A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/controllers/bas | Jul 20, 2025 | 9.8 | 24 | NO | NO |
CVE-2025-49089MEDIUM wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd. | Sep 15, 2025 | 6.3 | 22 | NO | NO |
CVE-2025-7896HIGH A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this vulnerability is the function download_video/delete_video of | Jul 20, 2025 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Harry0703.
Media articles that mention a CVE ID that affects a product developed by Harry0703 — matched by CVE ID, not by vendor name.