CVE-2025-41032: Apprain
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BAdmin%5D%5Busername%5D' parameter in /apprain/admin/manage/add/.
Affected products
- Apprain Apprain: version 4.0.5 only
Published 2025-09-04. Last modified 2026-06-17.