8.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
CVE-2025-68055 Authenticated SQL injection in Hydra Booking Plugin get function, Hydra Booking hardcodes user input directly into the raw sql request instead of using prepare to sanitize input, leading to Time-Based Blind SQL injection. Exploit A...
Basic Information
ID
1D922E85-3677-56DB-A3F0-D3BD5024D5D7
Published
Dec 19, 2025 at 10:01
Modified
Dec 19, 2025 at 10:02