CVE-2025-1981: Symfonia Ready
Critical severity, CVSS 9.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices module allows for SQL Injection attacks.
Affected products
- Symfonia Ready: from 7.0.0.0, up to and including 7.19.39.23; from 8.0.0.0, up to and including 8.0.2.3
Published 2025-04-16. Last modified 2026-06-17.