CVE-2025-25228

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
21/04/2025
Last modified:
28/05/2025

Description

A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:virtuemart:virtuemart:*:*:*:*:*:joomla\!:*:* 1.0.0 (including) 4.4.7 (including)