Kostasmitroglou maintains a small portfolio of applications centered on password management and system utilities, with an observed vulnerability pattern anchored in input-handling weaknesses. The recurring exposure centers on SQL injection, cross-site scripting, and OS command injection, reflecting inadequate sanitization of untrusted input across web-facing and system-level code paths. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kostasmitroglou over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25441CRITICAL thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the run_command | Feb 20, 2026 | 9.8 | 38 | NO | NO |
CVE-2019-25347HIGH thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL c | Feb 12, 2026 | 7.5 | 24 | NO | NO |
CVE-2019-25346HIGH TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Attackers can inject malicious SQL | Feb 12, 2026 | 7.5 | 24 | NO | NO |
CVE-2019-25311MEDIUM thesystem version 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple server data input fields. Attacker | Feb 11, 2026 | 6.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kostasmitroglou.
Media articles that mention a CVE ID that affects a product developed by Kostasmitroglou — matched by CVE ID, not by vendor name.