CVE-2025-49485

All FrameworksJoomlaCWE-89CVE-2025-49485

CVE-2025-49485

State: PUBLISHED · Published: 2025-07-18 · Updated: 2025-07-20 · Assigner: Joomla
Description
A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/49xxx/CVE-2025-49485.json