# Pro3W CMS Login Bypass via SQL Injection

Published: 2026-02-27 · Severity: medium
Canonical: https://vorant.io/reports/113a21d5-6e11-55ae-abbf-685eb47854db/pro3w-cms-login-bypass-via-sql-injection

> An unauthenticated SQL injection flaw in Pro3W CMS lets attackers bypass login and gain admin access.

CERT Polska coordinated disclosure of CVE-2025-15498, a SQL injection vulnerability in Pro3W CMS affecting version 1.2.0. The flaw stems from improper sanitization of input submitted through the login form, allowing an unauthenticated attacker to bypass authentication entirely and obtain administrative privileges on affected installations.

CERT Polska notes that the vendor did not respond during the coordination process, so the exact range of affected versions could not be confirmed. However, the issue is expected to be fixed in versions released from January 2026 onward. The vulnerability was reported by researcher Jacek Czepil and disclosed through CERT Polska's coordinated vulnerability disclosure process. There is no indication of active exploitation in the wild at this time.

## Mentioned in this report

- Vulnerabilities: CVE-2025-15498

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2025-15498

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/113a21d5-6e11-55ae-abbf-685eb47854db/pro3w-cms-login-bypass-via-sql-injection.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
