CVE-2026-25234 | pear pearweb up to 1.32.x Category Manager sql injection (GHSA-q28j-3p7r-6722)
A vulnerability labeled as critical has been found in pear pearweb up to 1.32.x. This affects an unknown part of the component Category Manager. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-25234. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.