CVE-2025-41006: Imaster Mems Events CRM

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.

Affected products

  • Imaster Mems Events CRM: any version

Published 2026-01-12. Last modified 2026-06-17.