CVE-2026-42425High· 7.2▾ TwilightOpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery interface. Attackers can submit …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery interface. Attackers can submit malicious SQL queries through the qs parameter to the /admin/DatabaseQuery endpoint to extract sensitive data including usernames and password hashes from the OKM_USER table, modify permissions, or delete database records.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13263Medium· 6.3A vulnerability was identified in SourceCodester Online Magazine Management System 1.0
CVE-2025-11611Medium· 6.3A weakness has been identified in SourceCodester Simple Inventory System 1.0
CVE-2025-10079High· 7.3A flaw has been found in PHPGurukul Small CRM 4.0
CVE-2025-13567Medium· 6.3A vulnerability was detected in itsourcecode COVID Tracking System 1.0
CVE-2025-13289Medium· 6.3A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0
CVE-2025-13290Medium· 6.3A vulnerability has been found in code-projects Simple Food Ordering System 1.0