CVE-2025-11438

Source
https://cve.org/CVERecord?id=CVE-2025-11438
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11438.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-11438
Published
2025-10-08T06:32:06.726Z
Modified
2026-08-12T03:51:26.998886986Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
JhumanJ OpnForm API Endpoint custom-domains authorization
Details

A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component API Endpoint. Such manipulation leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is beb153ce52dceb971c1518f98333328c95f1ba20. It is best practice to apply a patch to resolve this issue.

Database specific
{
    "cwe_ids": [
        "CWE-862",
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11438.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/OpnForm/OpnForm

Affected ranges

Type
GIT
Repo
https://github.com/OpnForm/OpnForm
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.9.0"
        },
        {
            "last_affected": "1.9.0"
        },
        {
            "introduced": "1.9.1"
        },
        {
            "last_affected": "1.9.1"
        },
        {
            "introduced": "1.9.2"
        },
        {
            "last_affected": "1.9.2"
        },
        {
            "introduced": "1.9.3"
        },
        {
            "last_affected": "1.9.3"
        }
    ]
}

Affected versions

1.*
1.9.0
1.9.1
1.9.2
1.9.3
v1.*
v1.9.0
v1.9.1
v1.9.2
v1.9.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11438.json"