A vulnerability labeled as critical has been found in Kohana KodiCMS up to 13.82.135. This affects the function
like of the file cms/modules/pages/classes/kodicms/model/page.php of the component Search API Endpoint. Executing manipulation of the argument keyword can lead to sql injection.
This vulnerability is registered as CVE-2025-15392. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Applying the suggested workaround is recommended.
The vendor was contacted early about this disclosure but did not respond in any way.