High severity8.2NVD Advisory· Published Apr 12, 2026· Updated Apr 17, 2026
CVE-2019-25697
CVE-2019-25697
Description
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to category.php with malicious cat_id values to extract sensitive database information including usernames and credentials.
Affected products
2cpe:2.3:a:victoralagwu:cmssite:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:victoralagwu:cmssite:1.0:*:*:*:*:*:*:*
- (no CPE)range: = 1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/46259nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/cmssite-sql-injection-via-category-phpnvdThird Party Advisory
News mentions
0No linked articles in our index yet.