CVE-2018-25319 is a high-severity (CVSS 3.1 base 7.1) SQL injection vulnerability in MyEvents, a third-party addon for Redaxo CMS, version 2.2.1. As with CVE-2018-25320 (ACL Analytics, covered separately), this is a 2018-dated CVE ID that only recently received formal NVD scoring — the flaw itself is not newly discovered.
What the vulnerability does
Per NVD’s description, an authenticated attacker can manipulate database queries by injecting SQL code through the myevents_id parameter. The documented attack path sends a GET request to the addon’s event_add.php page with a malicious myevents_id value, allowing extraction or modification of sensitive database information.
The CVSS vector reflects a network-reachable, low-complexity flaw requiring authentication (distinguishing it from the many unauthenticated SQL injection CVEs in this batch), with a confidentiality/integrity impact consistent with unauthorized database access via a CMS admin-area endpoint.
What we don’t yet have
This record traces to NVD’s reference set (the addon’s own GitHub repository, Exploit-DB, and VulnCheck’s advisory); no CISA KEV listing is present, and we don’t have confirmation of a patched version for the MyEvents addon specifically. Confidence is medium.
Why this matters
Because authentication is required, this is a lower-urgency finding than an unauthenticated SQL injection, but it’s still a real path to database compromise for any user account with access to the addon’s admin pages — including a lower-privileged CMS editor account that shouldn’t have full database access. Redaxo CMS installations using the MyEvents addon at or near version 2.2.1 should confirm whether a fixed version exists or, if the addon is no longer maintained, evaluate removing it.
Frequently Asked Questions
What is CVE-2018-25319?
A CVSS 7.1 high-severity SQL injection vulnerability in the MyEvents addon for Redaxo CMS, version 2.2.1, exploitable via the myevents_id parameter by an authenticated attacker.
Why does a 2018 CVE have a 2026 publish date in this article? NVD only recently assigned a CVSS score and formal analysis to this pre-existing, publicly disclosed vulnerability — the flaw itself is not new.
Is CVE-2018-25319 being actively exploited? Public exploit code has existed since the original disclosure, but it is not listed in CISA’s Known Exploited Vulnerabilities catalog as of this writing.
Data sourced from the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.