Junglewise Threat Intelligence

CVE-2025-10913: Saastech TemizlikYolda Cross-Site Scripting

CVE-2025-10913 · Severity: high · CVSS 8.3 · Published 2026-02-11

Executive brief

TemizlikYolda, an online cleaning and service platform, contains a security vulnerability that allows for cross-site scripting. An attacker could use this flaw to inject malicious scripts into the web application, potentially leading to unauthorized actions or the theft of user session information. The vendor has not responded to reports of this issue, and no official patch is currently available.

Technical details

A Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in the TemizlikYolda web application through version 11022026. The flaw stems from improper neutralization of user-supplied input during web page generation. According to the CVSS vector, the vulnerability is network-reachable and requires low-privileged authentication but notably does not require user interaction (UI:N), suggesting a stored XSS or similar variant that executes automatically. Successful exploitation could allow an attacker to compromise integrity and availability, with partial impact on confidentiality. As of the disclosure date, the vendor has not responded to the vulnerability report.

Affected products

  • Saastech Cleaning and Internet Services Inc. TemizlikYolda through 11022026

Timeline

  • 2026-02-11: disclosed
  • 2026-02-11: advisory: Advisory published by USOM/TR-CERT

References

Related threats