CVE-2025-1981: Symfonia Ready

Critical severity, CVSS 9.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices module allows for SQL Injection attacks.

Affected products

  • Symfonia Ready: from 7.0.0.0, up to and including 7.19.39.23; from 8.0.0.0, up to and including 8.0.2.3

Published 2025-04-16. Last modified 2026-06-17.