CVE-2026-25418: Bit Apps Bit Form

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.21.10.

Affected products

  • Bit Apps Bit Form: up to and including 2.21.10

Published 2026-02-19. Last modified 2026-06-17.