CVE-2025-3893: Jan Syski Megabip

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability.  Version 5.20 of MegaBIP fixes this issue.

Affected products

Published 2025-05-23. Last modified 2026-06-17.