CVE-2025-11439 is a missing authorization vulnerability affecting JhumanJ OpnForm versions up to 1.9.3, specifically within the /show/integrations file. This medium-severity vulnerability (CVSS 4.3) allows remote attackers with low privileges to exploit the flaw with low complexity, potentially leading to unauthorized access to sensitive information (CWE-862, CWE-863). While a public exploit exists and a patch (11d97d78f2de2cb49f79baed6bde8b611ec1f384) has been released, there is no evidence of active exploitation, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.9.3CPE matchmatch criteria | cpe:2.3:a:jhumanj:opnform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.