CVE-2025-25226
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
08/04/2025
Last modified:
04/06/2025
Description
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* | 1.0.0 (including) | 2.2.0 (excluding) |
| cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.4.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



