Critical severity9.8NVD Advisory· Published Feb 27, 2026· Updated Apr 16, 2026
CVE-2025-11252
CVE-2025-11252
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.This issue affects windesk.Fm: before v2.3.4. NOTE: The vendor patched the vulnerability after the CVE was published.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.usom.gov.tr/bildirim/tr-26-0085nvdThird Party Advisory
News mentions
0No linked articles in our index yet.