CVE-2018-25166Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to index.php with crafted SQL payloads in the search parameter to extract sensitive database information including usernames, database names, and version details.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-06); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Mentions · 2026-03-11: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-11: 103-0603-0703-11
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2018-25166 (CVSS:8.8, HIGH) is Awaiting Analysis. Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit..https://nvd.nist.gov/vuln/detail/CVE-2018-25166 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2018‑25166 as a high‑severity SQL injection vulnerability in Meneame English Pligg 5.8, noting that it is still awaiting analysis with no PoC or exploit details provided.

    0000039
    172 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2018-25166 - Sourceforge - Meneame English Pligg - https://www.redpacketsecurity.com/cve-alert-cve-2018-25166-sourceforge-meneame-english-pligg/ #OSINT #ThreatIntel #CyberSecurity #cve-2018-25166 #sourceforge #meneame-english-pligg

    Post summary

    The post announces a CVE alert for CVE-2018-25166 related to Sourceforge Meneame English Pligg, without providing any PoC, exploit, mitigation, or threat details.

    0000077
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2018-25166 Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code t… https://www.cve.org/CVERecord?id=CVE-2018-25166

    Post summary

    CVE‑2018‑25166 is an SQL injection flaw in Pligg 5.8 that permits unauthenticated attackers to execute arbitrary SQL queries. No PoC, exploit code, patch, or evidence of active exploitation is provided.

    00000109
    56.6K followersView on X

Explore more