PT-2025-51964 · Phpjabbers · Phpjabbers Simple Cms

Published

2025-12-17

·

Updated

2025-12-20

·

CVE-2023-53926

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPJabbers Simple CMS version 5.0
Description The software contains a SQL injection issue in the 'column' parameter. Attackers can inject crafted SQL payloads through the 'column' parameter in the ''index.php'' endpoint to potentially extract or modify database information. The vulnerable parameter is column.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-53926

Affected Products

Phpjabbers Simple Cms