CVE-2025-3893: Jan Syski Megabip
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability. Version 5.20 of MegaBIP fixes this issue.
Affected products
- Jan Syski Megabip: up to and including 5.19
Published 2025-05-23. Last modified 2026-06-17.