CVE-2026-25234: PEAR is Vulnerable to SQL Injection in Category Deletion
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion can allow an attacker with access to the category manager workflow to inject SQL via a category id. This issue has been patched in version 1.33.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25234?
CVE-2026-25234 is considered a high severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2026-25234?
To fix CVE-2026-25234, upgrade PEAR to version 1.33.0 or later.
What type of vulnerability is CVE-2026-25234?
CVE-2026-25234 is an SQL injection vulnerability affecting the category deletion functionality in PEAR.
Who is affected by CVE-2026-25234?
Organizations using PEAR framework versions prior to 1.33.0 are affected by CVE-2026-25234.
Can CVE-2026-25234 be exploited remotely?
Yes, an attacker with the necessary access can exploit CVE-2026-25234 remotely through the category manager workflow.