CVE-2025-43948

High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.

Published 2025-04-22. Last modified 2026-06-17.