Lkw199711's vulnerability profile centers on the Smanga product, a modestly represented offering whose disclosures cluster around authentication and access-control weaknesses including authorization bypass, improper authentication, path traversal, and OS command injection. These patterns reflect common vulnerabilities in applications handling user credentials and file or system access, and defenders should prioritize inventory and review of this product's deployment scope; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lkw199711 over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-70831CRITICAL A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The application fails to properly sanitize user-supplied input in the m | Feb 20, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-70833CRITICAL An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administrator) and fully takeover the acc | Feb 20, 2026 | 9.4 | 26 | NO | NO |
CVE-2024-34193HIGH smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file reading. | May 20, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lkw199711.
Media articles that mention a CVE ID that affects a product developed by Lkw199711 — matched by CVE ID, not by vendor name.