
Cloud Vulnerability DB
A community-led vulnerabilities database
A SQL injection vulnerability was discovered in Joomla's backend task list of com_scheduler component, identified as CVE-2025-22207. The vulnerability was reported on December 10, 2024, and fixed on February 18, 2025. It affects Joomla CMS versions 4.1.0-4.4.10 and 5.0.0-5.2.3, caused by improperly built order clauses (Joomla Security).
The vulnerability has been assigned a CVSS v4.0 score of 6.7 (MEDIUM) with the vector string CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N. The vulnerability is classified under CWE-89, which refers to Improper Neutralization of Special Elements used in an SQL Command (NVD Database).
The vulnerability allows for SQL injection attacks specifically in the backend task list of the scheduler component. While the vulnerability has high impact potential for confidentiality (VC:H), it shows no impact on integrity (VI:N) or availability (VA:N) according to the CVSS metrics (NVD Database).
The recommended mitigation is to upgrade to Joomla version 4.4.11 or 5.2.4, which contains the security fix for this vulnerability (Joomla Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."