Jettweb develops a suite of PHP-based website templates and scripts for common e-commerce and content-management use cases, including news sites, rental platforms, and advertising portals, with a narrow product footprint concentrated in server-side web applications. Vulnerabilities affecting this vendor skew strongly toward critical severity and recur consistently through SQL injection weaknesses, reflecting inadequate input sanitization in the underlying PHP application logic. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jettweb over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25520CRITICAL Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated attackers to gain administrative a | Mar 12, 2026 | 9.8 | 31 | NO | NO |
CVE-2019-25515CRITICAL Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an authentication bypass vulnerability in the login.php administration panel that allows unauthenticated attackers to gain admini | Mar 12, 2026 | 9.8 | 30 | NO | NO |
CVE-2019-25514CRITICAL Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the kelime parameter in POST reques | Mar 12, 2026 | 9.8 | 30 | NO | NO |
CVE-2019-25513CRITICAL Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through | Mar 12, 2026 | 9.8 | 30 | NO | NO |
CVE-2019-25510CRITICAL Jettweb PHP Hazir Haber Sitesi Scripti V2 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated attackers to gain administrative a | Mar 12, 2026 | 9.8 | 30 | NO | NO |
CVE-2019-25488CRITICAL Jettweb Hazir Rent A Car Scripti V4 contains multiple SQL injection vulnerabilities in the admin panel that allow unauthenticated attackers to manipulate database queries through G | Mar 12, 2026 | 9.8 | 30 | NO | NO |
CVE-2019-25519HIGH Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the o | Mar 12, 2026 | 8.2 | 27 | NO | NO |
CVE-2019-25518HIGH Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through | Mar 12, 2026 | 8.2 | 26 | NO | NO |
CVE-2019-25517HIGH Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through | Mar 12, 2026 | 8.2 | 26 | NO | NO |
CVE-2019-25512HIGH Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the kelime parameter in POST reques | Mar 12, 2026 | 8.2 | 26 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jettweb.
Media articles that mention a CVE ID that affects a product developed by Jettweb — matched by CVE ID, not by vendor name.