CVE-2025-51655: SQL Injection
Published Jul 14, 2025
·Updated
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMSQuanxian.php.
Affected Software
2 affected components
SEMCMS SEMCMS
Sem-cms Semcms<=5.0
Event History
Jul 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-51655?
CVE-2025-51655 is classified as a critical SQL injection vulnerability that can lead to unauthorized access to sensitive data.
2
How do I fix CVE-2025-51655?
To remediate CVE-2025-51655, update SemCms to the latest version that addresses this SQL injection flaw.
3
What is the impact of CVE-2025-51655?
The impact of CVE-2025-51655 includes potential exposure of database information and possible remote code execution.
4
What version of SemCms is affected by CVE-2025-51655?
CVE-2025-51655 affects SemCms version 5.0 and earlier.
5
What specific parameter is exploited in CVE-2025-51655?
CVE-2025-51655 can be exploited through the 'pid' parameter in the SEMCMS_Quanxian.php file.