CVE-2025-54865

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
05/08/2025
Last modified:
09/10/2025

Description

Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ftb-gamepedia:tilesheets:*:*:*:*:*:mediawiki:*:* 5.0.1 (including) 5.0.3 (excluding)