PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-25757 Joomla CVE debrief

CVE-2019-25757 is an SQL injection vulnerability in Joomla vWishlist 1.0.1. Authenticated attackers can inject malicious SQL code through the vproductid and userid parameters. This allows them to execute arbitrary SQL queries and extract sensitive database information, including version and database names. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Defenders should assess their exposure and prioritize patching or mitigation.

Vendor
Joomla
Product
vWishlist 1.0.1
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-19
Original CVE updated
2026-08-21
Advisory published
2026-06-19
Advisory updated
2026-08-21

Who should care

Administrators and security teams responsible for Joomla installations, particularly those using vWishlist 1.0.1, should be aware of this vulnerability. Authenticated attackers can exploit this vulnerability to access sensitive database information, potentially leading to further attacks or data breaches.

Technical summary

The vulnerability exists in the vWishlist 1.0.1 component for Joomla. An attacker can send POST requests to the component with crafted SQL payloads in the vproductid and userid parameters to inject malicious SQL code. This allows them to execute arbitrary SQL queries and extract sensitive database information. The CVSS vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.

Defensive priority

High priority due to potential for sensitive data exposure and further attacks

Recommended defensive actions

  • Inventory Joomla installations for vWishlist 1.0.1
  • Review official advisories for patch availability and apply if present
  • Limit exposure by restricting access to the vWishlist component
  • Monitor for suspicious SQL queries and database access attempts
  • Implement compensating controls such as web application firewalls

Evidence notes

The primary evidence for this vulnerability comes from the CVE-2019-25757 record and the NVD detail page. The vulnerability affects Joomla vWishlist 1.0.1. Defenders should verify the version of vWishlist installed and check for official patches or advisories from the vendor.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-25757 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-25757

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-25757 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-25757

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.