CVE-2025-41441: Synck Mailform Pro Cgi
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the coupon feature.
Affected products
- Synck Mailform Pro Cgi: before 4.3.4 (fixed in 4.3.4)
Published 2025-05-26. Last modified 2026-06-17.