Security Advisory

CVE-2026-51925

8.1
HIGH

Vulnerability Description

A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive configuration files, source code or system files.
Published Date July 9, 2026
Official Source NIST NVD Advisory