CVE-2026-25238: PEAR is Vulnerable to SQL Injection in Bug Subscription Deletion via Weak Email Validation
Published Feb 3, 2026
·Updated
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to inject SQL via a crafted email value. This issue has been patched in version 1.33.0.
Affected Software
2 affected components
PEAR PEAR<1.33.0
PEAR Pearweb<1.33.0
Event History
Feb 3, 2026
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 19, 58090
Event
via FIRST·09:26 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-25238?
CVE-2026-25238 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2026-25238?
To remediate CVE-2026-25238, you should update PEAR to version 1.33.0 or later.
3
What are the potential impacts of CVE-2026-25238?
CVE-2026-25238 can allow attackers to execute arbitrary SQL queries, potentially leading to data breaches.
4
Which versions of PEAR are affected by CVE-2026-25238?
CVE-2026-25238 affects all versions of PEAR prior to 1.33.0.
5
How can I confirm if my PEAR installation is vulnerable to CVE-2026-25238?
You can check your PEAR version against the vulnerability details to determine if it falls below 1.33.0.