---
id: CVE-2025-11440
title: A vulnerability was determined in JhumanJ OpnForm up to 1.9.3
summary: >-
  A vulnerability was determined in JhumanJ OpnForm up to 1.9.3. Impacted is an
  unknown function of the file /edit. Executing manipulation can lead to
  improper access controls. The attack can be executed remotely. The exploit has
  been publ…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-266
  - CWE-284
vendor: jhumanj
product: opnform
affected:
  - opnform <= 1.9.3
published: '2025-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11440'
references:
  - url: >-
      https://docs.google.com/document/d/1GUjJA9vUbsXUngAv6ySsbCIhVynf8_djardLZYEDOe0/edit?tab=t.0#heading=h.t78mmp24qqk5
    label: cna@vuldb.com
  - url: >-
      https://github.com/JhumanJ/OpnForm/pull/900/commits/b15e29021d326be127193a5dbbd528c4e37e6324
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327377'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327377'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.666881'
    label: cna@vuldb.com
  - url: >-
      https://docs.google.com/document/d/1GUjJA9vUbsXUngAv6ySsbCIhVynf8_djardLZYEDOe0/edit?tab=t.0#heading=h.t78mmp24qqk5
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00352
epssPercentile: 0.26814
ingestedAt: '2026-10-08T13:42:54.998Z'
---

## Overview

A vulnerability was determined in JhumanJ OpnForm up to 1.9.3. Impacted is an unknown function of the file /edit. Executing manipulation can lead to improper access controls. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This patch is called b15e29021d326be127193a5dbbd528c4e37e6324. Applying a patch is advised to resolve this issue.

## Affected

- `opnform <= 1.9.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
