# DobryCMS patches SQLi and RCE flaws

Published: 2026-03-02 · Severity: medium
Canonical: https://vorant.io/reports/eeb58c24-d960-5f45-8322-a11397c8ffc0/dobrycms-patches-sqli-and-rce-flaws

> CERT Polska coordinated disclosure of two DobryCMS vulnerabilities allowing unauthenticated blind SQL injection and unrestricted file upload leading to RCE.

CERT Polska disclosed two vulnerabilities in DobryCMS software following coordinated vulnerability disclosure. CVE-2025-12462 is a blind SQL injection flaw exploitable by an unauthenticated remote attacker via URL path parameters, fixed in versions above 8.0. CVE-2025-14532 is an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary file types, potentially leading to remote code execution, fixed in versions above 5.0.

Both issues were responsibly reported by named researchers and coordinated through CERT Polska's disclosure process. There is no indication of active exploitation in the wild; this is a standard patch advisory for a CMS product with no evidence of a threat actor or campaign involved.

## Mentioned in this report

- Vulnerabilities: CVE-2025-12462, CVE-2025-14532

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-12462

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/eeb58c24-d960-5f45-8322-a11397c8ffc0/dobrycms-patches-sqli-and-rce-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
