CVE-2025-39380: Mojoomla Hospital Management System

Critical severity, CVSS 10.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System hospital-management allows Upload a Web Shell to a Web Server.This issue affects Hospital Management System: from n/a through <= 47.0(20-11-2023).

Affected products

  • Mojoomla Hospital Management System: up to and including 47.0(20-11-2023)

Published 2025-05-19. Last modified 2026-06-17.