CVE-2025-46052: Weberp

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive data by injecting a crafted payload into the DEL form field in a POST request to /StockCounts.php

Affected products

  • Weberp Weberp: version 4.15.2 only

Published 2025-05-15. Last modified 2026-06-17.