Low severity3.8NVD Advisory· Published Apr 21, 2025· Updated Jun 17, 2026
CVE-2025-25228
CVE-2025-25228
Description
A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:virtuemart:virtuemart:*:*:*:*:*:joomla\!:*:*+ 1 more
- cpe:2.3:a:virtuemart:virtuemart:*:*:*:*:*:joomla\!:*:*range: >=1.0.0,<=4.4.7
- (no CPE)range: 1.0.0 - 4.4.7
- Range: 1.0.0-4.4.8
Patches
Vulnerability mechanics
References
2- github.com/AdamWallwork/CVEs/tree/main/2025/CVE-2025-25228nvdBroken Link
- virtuemart.netnvdProduct
News mentions
0No linked articles in our index yet.