CVE-2026-25239: PEAR is Vulnerable to SQL Injection in apidoc_queue Insert via Unescaped Filename
Published Feb 3, 2026
·Updated
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in apidoc queue insertion can allow query manipulation if an attacker can influence the inserted filename value. This issue has been patched in version 1.33.0.
Affected Software
2 affected components
pear/pear<1.33.0
PEAR Pearweb<1.33.0
Event History
Feb 3, 2026
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 19, 58090
Event
via FIRST·08:24 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-25239?
CVE-2026-25239 has a medium severity rating due to its potential for SQL injection exploitation.
2
What software versions are affected by CVE-2026-25239?
CVE-2026-25239 affects PEAR versions prior to 1.33.0.
3
How do I fix CVE-2026-25239?
To fix CVE-2026-25239, upgrade PEAR to version 1.33.0 or later.
4
What is the nature of the vulnerability in CVE-2026-25239?
CVE-2026-25239 is a SQL injection vulnerability found in the apidoc queue insertion process.
5
How can an attacker exploit CVE-2026-25239?
An attacker can exploit CVE-2026-25239 by influencing the input data to manipulate SQL queries.