Description
SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission to execute arbitrary SQL commands via the categories_order parameter.
Remediation
References
Related Vulnerabilities
CrushFTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-32102)
Moodle Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-21809)
WordPress Plugin Permalink Manager Lite Unspecified Vulnerability (2.2.13.1)
WordPress Plugin Oi Yandex.Maps for WordPress Cross-Site Scripting (3.2.7)