CVE-2025-10856
HIGHCVSS 8.1/10EPSS 0.32%
Last modified
CVE-2025-10856 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows File Content Injection. This issue affects Teknoera: through 01102025.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows File Content Injection. This issue affects Teknoera: through 01102025.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-10856?
Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows File Content Injection.
This issue affects Teknoera: through 01102025.
How severe is CVE-2025-10856?
CVE-2025-10856 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 0.32% probability of exploitation in the next 30 days.
How do I fix CVE-2025-10856?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-1085A vulnerability, which was classified as problematic, was fo…5.3
- CVE-2025-10850The Felan Framework plugin for WordPress is vulnerable to im…9.8
- CVE-2025-10851A security flaw has been discovered in Campcodes Gym Managem…9.8
- CVE-2025-10853A reflected cross-site scripting (XSS) vulnerability exists …6.1
- CVE-2025-10854The txtai framework allows the loading of compressed tar fil…8.1
- CVE-2025-10855Authorization Bypass Through User-Controlled Key vulnerabili…7.5
- CVE-2025-10857A security flaw has been discovered in Campcodes Point of Sa…9.8
- CVE-2025-10858An issue was discovered in GitLab CE/EE affecting all versio…7.5
- CVE-2025-10859Cookie storage for non-HTML temporary documents was being sh…4
- CVE-2025-1086A vulnerability has been found in Safetytest Cloud-Master Se…6.9
- CVE-2025-10861The Popup builder with Gamification, Multi-Step Popups, Page…7.5
- CVE-2025-10862The Popup builder with Gamification, Multi-Step Popups, Page…7.5
Are you affected by CVE-2025-10856?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
