CVE-2025-12462: Studio Fabryka Dobrycms
Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in multiple parameters resulting in Blind SQL Injection. This issue was fixed in versions above 8.0.
Affected products
- Studio Fabryka Dobrycms: before 8.0 (fixed in 8.0)
Published 2026-03-02. Last modified 2026-06-17.