---
id: CVE-2019-25753
title: Joomla! Component VMap 1.9.6 SQL Injection via loadmarker
summary: >-
  Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that
  allows unauthenticated attackers to execute arbitrary SQL queries by injecting
  malicious code into the latlngbound parameter. Attackers can send GET requests
  to in…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-89
vendor: Wdmtech
product: VMap
affected:
  - VMap 1.9.6
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-06-22T17:03:17.992945Z'
exploitAvailable: true
published: '2026-06-19'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:25.920Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2019-25753'
references:
  - url: 'https://www.exploit-db.com/exploits/46229'
    label: ExploitDB-46229
  - url: 'http://wdmtech.com/'
    label: Official Product Homepage
  - url: >-
      https://extensions.joomla.org/extensions/extension/maps-a-weather/maps-a-locations/vmap/
    label: Product Reference
  - url: >-
      https://www.vulncheck.com/advisories/joomla-component-vmap-sql-injection-via-loadmarker
    label: >-
      VulnCheck Advisory: Joomla! Component VMap 1.9.6 SQL Injection via
      loadmarker
tags:
  - cve.org
  - exploit-available
epss: 0.00492
epssPercentile: 0.40018
ingestedAt: '2026-10-01T15:48:17.881Z'
---

## Overview

Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the latlngbound parameter. Attackers can send GET requests to index.php with the option=com_vmap&task=loadmarker parameters containing SQL injection payloads to manipulate database queries and extract sensitive information.

## Affected

- `VMap 1.9.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
