Web Ofisi develops a focused suite of Turkish business and e-commerce applications spanning product categories such as e-commerce platforms, real-estate management, firm directories, and related web services. The vulnerability footprint is narrow and centered on this specific vendor's application portfolio, with no consistent pattern of weakness-class clustering identified across its disclosures. Current exposure counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Web Ofisi over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25459CRITICAL Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database queries through GET parameters. Attac | Feb 22, 2026 | 9.8 | 31 | NO | NO |
CVE-2019-25458CRITICAL Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters | Feb 22, 2026 | 9.8 | 31 | NO | NO |
CVE-2019-25456CRITICAL Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET paramete | Feb 22, 2026 | 9.1 | 30 | NO | NO |
CVE-2018-25210HIGH WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to manipulate database queries. Att | Mar 26, 2026 | 8.2 | 26 | NO | NO |
CVE-2019-25461HIGH Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' p | Feb 22, 2026 | 7.5 | 26 | NO | NO |
CVE-2019-25460HIGH Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' G | Feb 22, 2026 | 7.5 | 26 | NO | NO |
CVE-2019-25457HIGH Web Ofisi Firma v13 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'oz' array parame | Feb 22, 2026 | 7.5 | 26 | NO | NO |
CVE-2019-25455HIGH Web Ofisi E-Ticaret v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'a' parameter. | Feb 22, 2026 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Web Ofisi.
Media articles that mention a CVE ID that affects a product developed by Web Ofisi — matched by CVE ID, not by vendor name.