CVE-2023-48925: Buy-Addons Bavideotab

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().

Affected products

  • Buy-Addons Bavideotab: before 1.0.6 (fixed in 1.0.6)

Published 2023-12-14. Last modified 2026-06-17.