LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2019-25642

CVE-2019-25642 - Vulnerability Analysis

HighCVSS: 8.2

Last Updated: March 24, 2026

Bootstrapy CMS - SQL Injection

Published: March 24, 2026Updated: March 24, 2026Remote Exploitable

Overview

Bootstrapy CMS contains multiple sql injection vulnerabilities caused by unsanitized POST parameters (thread_id, subject, post-id) in various scripts, letting unauthenticated attackers execute arbitrary SQL queries and extract sensitive data or cause denial of service.

Severity & Score

Severity: High
CVSS Score: 8.2

Impact

Unauthenticated attackers can execute arbitrary SQL queries, leading to data disclosure or denial of service.

Mitigation

Update Bootstrapy CMS to the latest version with SQL injection fixes.

Details

CVE ID
CVE-2019-25642
Severity
High
CVSS Score
8.2
Type
sql_injection
Status
new

CWE

  • CWE-89

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N