| CVE ID | CVE-2025-8536 |
| Publication date | 24 October 2025 |
| Vendor | Studio Fabryka |
| Product | DobryCMS |
| Vulnerable versions | 1.x and 2.x |
| Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Studio Fabryka DobryCMS software and participated in coordination of its disclosure.
The vulnerability CVE-2025-8536: A SQL injection vulnerability has been identified in DobryCMS. Improper neutralization of input provided by user into language change functionality allows for SQL Injection attacks.
Credits
We thank Dawid Radziński from RED SECURITY for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.