CVE-2025-11438Medium· 6.3▾ SunlitA vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component API Endpoint. Such manipulation leads to missing authorization. The attack may be launche…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component API Endpoint. Such manipulation leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is beb153ce52dceb971c1518f98333328c95f1ba20. It is best practice to apply a patch to resolve this issue.
opnform <= 1.9.3Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-11439Medium· 4.3A vulnerability was found in JhumanJ OpnForm up to 1.9.3
CVE-2025-11442Medium· 4.3A security flaw has been discovered in JhumanJ OpnForm up to 1.9.3
CVE-2025-12924Medium· 4.3A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224
CVE-2025-11443Low· 3.7A weakness has been identified in JhumanJ OpnForm up to 1.9.3
CVE-2025-11440Medium· 4.3A vulnerability was determined in JhumanJ OpnForm up to 1.9.3
CVE-2025-11441Low· 3.7A vulnerability was identified in JhumanJ OpnForm up to 1.9.3