home.social

#sqlinjection — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sqlinjection, aggregated by home.social.

  1. Unauthenticated SQL Injection (CVE-2026-41555, CRITICAL, CVSS 9.3) in Weblizar Newsletter Subscription Form <=1.5.9 impacts WordPress sites. Patch status unknown — restrict/disable the component. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #SQLInjection

  2. CRITICAL SQL injection (CVE-2026-42415) in p-themes Porto Theme - Functionality ≤3.9.3. Unauthenticated attackers can steal sensitive data. No official patch yet — restrict access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202642415 #Infosec #WordPress #SQLInjection

  3. CVE-2026-42417 (CRITICAL): ARMember Premium <= 7.8 is vulnerable to unauthenticated SQL Injection (CWE-89). No mitigation yet — review deployments & monitor databases closely. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #SQLInjection #WordPress

Share on Mastodon

Enter the server where you have an account.