CVE-2025-7385: Concept Intermedia Gov CMS
Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker. Versions 4.0 and above are not affected.
Affected products
- Concept Intermedia Gov CMS: before 4.0 (fixed in 4.0)
Published 2025-09-04. Last modified 2026-06-17.