SQL Injection Vulnerability in PHPJabbers Simple CMS by PHPJabbers
CVE-2023-53926
Key Information:
- Vendor
PHPjabbers
- Status
- Vendor
- CVE Published:
- 17 December 2025
Badges
What is CVE-2023-53926?
PHPJabbers Simple CMS 5.0 is vulnerable to a SQL injection flaw that arises from improper handling of the 'column' parameter in the index.php endpoint. This weakness allows remote attackers to inject malicious SQL queries, potentially leading to unauthorized access to sensitive database information. Attackers can exploit this vulnerability to execute arbitrary SQL commands, which could result in the alteration, extraction, or deletion of critical data.
Affected Version(s)
Simple CMS 5.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
