CVE-2025-54865

Source
https://cve.org/CVERecord?id=CVE-2025-54865
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54865.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54865
Aliases
  • GHSA-hqfr-7cm9-4h87
Published
2025-08-05T00:03:46.948Z
Modified
2026-04-02T12:54:05.037542Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Tilesheets MediaWiki Extension is Vulnerable to Potential SQL Injection
Details

Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54865.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/ftb-gamepedia/tilesheets

Affected ranges

Type
GIT
Repo
https://github.com/ftb-gamepedia/tilesheets
Events

Affected versions

5.*
5.0.1
5.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54865.json"