DobryCMS patches SQLi and RCE flaws
CERT Polska coordinated disclosure of two DobryCMS vulnerabilities allowing unauthenticated blind SQL injection and unrestricted file upload leading to RCE.
CERT Polska disclosed two vulnerabilities in DobryCMS software following coordinated vulnerability disclosure. CVE-2025-12462 is a blind SQL injection flaw exploitable by an unauthenticated remote attacker via URL path parameters, fixed in versions above 8.0. CVE-2025-14532 is an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary file types, potentially leading to remote code execution, fixed in versions above 5.0.
Both issues were responsibly reported by named researchers and coordinated through CERT Polska's disclosure process. There is no indication of active exploitation in the wild; this is a standard patch advisory for a CMS product with no evidence of a threat actor or campaign involved.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-12462
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free