CVE-2025-15498 - CVE House
Back to Database
Status published Critical CVE-2025-15498

SQL Injection in Pro3W CMS

Vulnerability Description

Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to bypass authentication and gain administrative privileges.  This issue was identified in version 1.2.0 of this software. Due to lack of response from the vendor exact version range could not be determined, but the vulnerability should be eliminated in versions released in January 2026 and later.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15498

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Jacek Czepil

Affected Vendor

Affected Software

Pro3W CMS
Vulnerable Versions:
0

Timeline

Official Publish: February 27th, 2026
Last Modified: February 27th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)