CVE-2026-41460 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: April 23, 2026
SocialEngine - SQL Injection
Published: April 23, 2026Updated: April 23, 2026Remote Exploitable
Overview
SocialEngine <= 7.8.0 contains a sql injection caused by unsanitized user input in the text parameter of /activity/index/get-memberall endpoint, letting unauthenticated remote attackers read data, reset admin passwords, and gain unauthorized admin access.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Unauthenticated attackers can read database data, reset admin passwords, and gain admin access, potentially leading to remote code execution.
Mitigation
Update to the latest version beyond 7.8.0.
References
Related Resources
Details
- CVE ID
- CVE-2026-41460
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- sql_injection
- Status
- new
CWE
- CWE-89
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H