CVE-2025-54865

HIGH

Tilesheets 5.0.1-5.0.3 - SQL Injection via Missing Backtick in Query

Title source: llm
STIX 2.1

Description

Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.

Scores

CVSS v3 7.3
EPSS 0.0036
EPSS Percentile 27.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
ftb-gamepedia/tilesheets 5.0.1 - 5.0.3
Published Aug 05, 2025
Tracked Since Feb 18, 2026