CVE-2018-25199Disclosure(tomalofficial / php_oop_cms_blog)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameters. Attackers can inject SQL commands via the search parameter in search.php, pageid parameter in page.php, and id parameter in posts.php to extract database information including table names, schema names, and database credentials.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php_oop_cms_blog

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
php_oop_cms_blog

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-06: 2Technical Details · 2026-03-06: 203-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2018-25199 OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through mult… https://www.cve.org/CVERecord?id=CVE-2018-25199

    Post summary

    The text describes a disclosed SQL injection vulnerability in OOP CMS Blog 1.0, detailing how unauthenticated attackers can run arbitrary SQL queries, but provides no PoC, exploit code, or active usage information.

    0000085
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2018-25199 OOP CMS BLOG 1.0 SQL Injection via search parameter Intel Report: https://ift.tt/AQ9BiMl

    Post summary

    An alert is issued for CVE-2018-25199, highlighting an SQL injection flaw in OOP CMS Blog 1.0 via the search parameter; the post lacks PoC, exploit, patch, or active usage details.

    0000030
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptomalofficialphp_oop_cms_blog1.0--

Explore more