CVE-2025-51654: SQL Injection
Published Jul 14, 2025
·Updated
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMSInfocategories.php.
Affected Software
2 affected components
SEMCMS SEMCMS
Sem-cms Semcms<=5.0
Event History
Jul 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-51654?
CVE-2025-51654 has a high severity rating due to its potential to allow attackers to execute arbitrary SQL queries.
2
How do I fix CVE-2025-51654?
To fix CVE-2025-51654, sanitize input parameters to the SEMCMS_Infocategories.php file to prevent SQL injection attacks.
3
Which software versions are affected by CVE-2025-51654?
CVE-2025-51654 affects SemCms v5.0 and earlier versions.
4
What type of vulnerability is CVE-2025-51654?
CVE-2025-51654 is classified as a SQL injection vulnerability.
5
Where can I find more information on CVE-2025-51654?
More information on CVE-2025-51654 can be obtained from security advisories related to SemCms.