CVE-2026-36962
Last modified
CVE-2026-36962 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative access, and potentially gain remote code execution by writing malicious files to the server's file system via the keyword parameter in the /index/controller/Search.php endpoint.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative access, and potentially gain remote code execution by writing malicious files to the server's file system via the keyword parameter in the /index/controller/Search.php endpoint.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-36962?
How severe is CVE-2026-36962?
How do I fix CVE-2026-36962?
Are you affected by CVE-2026-36962?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
