CVE-2025-39386: Mojoomla Hospital Management System

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System hospital-management allows SQL Injection.This issue affects Hospital Management System: from n/a through <= 47.0(20-11-2023).

Affected products

  • Mojoomla Hospital Management System: up to and including 47.0(20-11-2023)

Published 2025-05-19. Last modified 2026-06-17.