CVE-2025-29411: Martmbithi Ibanking

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Affected products

Published 2025-03-20. Last modified 2026-06-17.