Security Advisory
CVE-2026-51925
8.1
HIGH
Vulnerability Description
A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive configuration files, source code or system files.
Published Date
July 9, 2026
Official Source
NIST NVD Advisory