| CVE ID | CVE-2025-15498 |
| Publication date | 27 February 2026 |
| Vendor | Pro3W |
| Product | Pro3W CMS |
| Vulnerable versions | All through 1.2.0 |
| Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Pro3W CMS software and participated in coordination of its disclosure.
The vulnerability CVE-2025-15498: Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to bypass authentication and gain administrative privileges.
This issue was identified in version 1.2.0 of this software. Due to lack of response from the vendor exact version range could not be determined, but the vulnerability should be eliminated in versions released in January 2026 and later.
Credits
We thank Jacek Czepil for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.