A vulnerability has been found in VX Guestbook 1.07 and classified as critical. This impacts an unknown function of the file words.php of the component POST Parameter Handler. This manipulation of the argument word causes sql injection.

This vulnerability is tracked as CVE-2025-57263. The attack is possible to be carried out remotely. No exploit exists.