CVE-2019-25757

HIGH

Joomla vWishlist 1.0.1 SQL Injection via vproductid Parameter

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25757. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in Joomla! Component vWishlist 1.0.1 via crafted POST requests. The payloads use URL-encoded SQL syntax to trigger errors, confirming the vulnerability.

Description

Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid parameters. Attackers can send POST requests to the component with crafted SQL payloads in these parameters to extract sensitive database information including version and database names.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/46225

The exploit demonstrates a SQL injection vulnerability in Joomla! Component vWishlist 1.0.1 via crafted POST requests. The payloads use URL-encoded SQL syntax to trigger errors, confirming the vulnerability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Joomla! Component vWishlist 1.0.1
Auth required
Prerequisites: Authenticated session (valid cookies) · Target running Joomla! with vWishlist 1.0.1
devstral-2 · analyzed Jun 19, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46225
https://www.exploit-db.com/exploits/46225
Product product
Official Product Homepage
http://wdmtech.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Joomla vWishlist 1.0.1 SQL Injection via vproductid Parameter
https://www.vulncheck.com/advisories/joomla-vwishlist-sql-injection-via-vproductid-parameter

Scores

CVSS v3 7.1
EPSS 0.0022
EPSS Percentile 12.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Wdmtech/vWishlist 1.0.1
Published Jun 19, 2026
Tracked Since Jun 19, 2026