PT-2026-21136 · Teconcetheme · Saasplate Core

Published

2026-02-20

·

Updated

2026-02-22

·

CVE-2025-69309

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions TeconceTheme Saasplate Core versions through 1.2.8
Description A flaw exists in TeconceTheme Saasplate Core saasplate-core that allows for Blind SQL Injection due to improper neutralization of special elements used in an SQL command. This issue could potentially allow an attacker to gain unauthorized access to sensitive data.
Recommendations Update TeconceTheme Saasplate Core to a version later than 1.2.8.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-69309

Affected Products

Saasplate Core