CVE-2025-41005: Imaster Mems Events CRM

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.php’.

Affected products

  • Imaster Mems Events CRM: any version

Published 2026-01-12. Last modified 2026-06-17.