CVE-2025-54865
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
05/08/2025
Last modified:
09/10/2025
Description
Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.
Impact
Base Score 3.x
7.30
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ftb-gamepedia:tilesheets:*:*:*:*:*:mediawiki:*:* | 5.0.1 (including) | 5.0.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



