VORANT. Threat Intelligence Sign in Get the full feed

DobryCMS patches SQLi and RCE flaws

medium vulnerability

CERT Polska coordinated disclosure of two DobryCMS vulnerabilities allowing unauthenticated blind SQL injection and unrestricted file upload leading to RCE.

CERT Polska disclosed two vulnerabilities in DobryCMS software following coordinated vulnerability disclosure. CVE-2025-12462 is a blind SQL injection flaw exploitable by an unauthenticated remote attacker via URL path parameters, fixed in versions above 8.0. CVE-2025-14532 is an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary file types, potentially leading to remote code execution, fixed in versions above 5.0.

Both issues were responsibly reported by named researchers and coordinated through CERT Polska's disclosure process. There is no indication of active exploitation in the wild; this is a standard patch advisory for a CMS product with no evidence of a threat actor or campaign involved.

Mentioned in this report

Vulnerabilities CVE-2025-12462CVE-2025-14532

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-12462

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free