joomla/database
Joomla Database Package
Activity
- Latest release
- 6mo ago
- Total releases
- 40
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- unknown
- First release
- Jun 04, 2013
| Version | Released | |
|---|---|---|
3.4.4
patch
| ||
4.0.0
major
| ||
3.4.3
patch
| ||
3.4.2
patch
| ||
3.4.1
patch
| ||
2.2.1
patch
| ||
2.2.0
minor
| ||
3.4.0
minor
| ||
3.3.1
patch
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
3.3.0
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
3.2.1
patch
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
3.2.0
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
3.1.0
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
3.0.0
major
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
2.0.2
patch
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.8.0
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
2.0.0-beta3
pre
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
2.0.0-beta2
pre
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
2.0.0-beta
pre
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.7.1
patch
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.7.0
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.4.2
patch
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.4.1
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.2.1
patch
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.1.2
patch
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.1.1
patch
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.0
initial
1 CVE
CVE-2025-25226
GHSA-44v2-prcf-pc3m
BIT-joomla-2025-25226
Apr 08, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Medium
Network
Low
None
None
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Affected versions
3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
+ 18 more Show less
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-rc
2.0.1
2.0.2
2.1.0
2.1.1
Fixed in
2.2.0
3.4.0
References Updated Jun 05, 2025 · Source: OSV.dev | ||
1.0-beta3
pre
| ||
1.0-beta2
pre
| ||
1.0-beta
pre
| ||
1.0-alpha
pre
|