CVE-2026-25238 | pear pearweb up to 1.32.x Bug Subscription Deletion email sql injection (GHSA-cv3c-27h5-7gmv / Nessus ID 297894)
A vulnerability classified as critical has been found in pear pearweb up to 1.32.x. Impacted is an unknown function of the component Bug Subscription Deletion. The manipulation of the argument email leads to sql injection.
This vulnerability is listed as CVE-2026-25238. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.