CVE-2026-25239

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in apidoc queue insertion can allow query manipulation if an attacker can influence the inserted filename value. This issue has been patched in version 1.33.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pear:pearweb:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:24

Type Values Removed Values Added
Summary
  • (es) PEAR es un framework y sistema de distribución para componentes PHP reutilizables. Antes de la versión 1.33.0, una vulnerabilidad de inyección SQL en la inserción de la cola de apidoc puede permitir la manipulación de consultas si un atacante puede influir en el valor del nombre de archivo insertado. Este problema ha sido parcheado en la versión 1.33.0.

05 Feb 2026, 18:00

Type Values Removed Values Added
First Time Pear
Pear pearweb
References () https://github.com/pear/pearweb/security/advisories/GHSA-f9mg-x463-3vxg - () https://github.com/pear/pearweb/security/advisories/GHSA-f9mg-x463-3vxg - Vendor Advisory
CPE cpe:2.3:a:pear:pearweb:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

03 Feb 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 19:16

Updated : 2026-06-17 10:24


NVD link : CVE-2026-25239

Mitre link : CVE-2026-25239

CVE.ORG link : CVE-2026-25239


JSON object : View

Products Affected

pear

  • pearweb
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')