PT-2026-34664 · Unknown · Socialengine

Egidio Romano

·

Published

2026-04-23

·

Updated

2026-04-27

·

CVE-2026-41460

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SocialEngine versions 7.8.0 and prior
Description An issue exists in the '/activity/index/get-memberall' endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. This allows an unauthenticated remote attacker to read arbitrary data from the database, reset administrator account passwords, and gain unauthorized access to the Packages Manager in the Admin Panel, which could potentially enable remote code execution.
Recommendations Update SocialEngine to a version later than 7.8.0. Avoid using the text parameter in the '/activity/index/get-memberall' endpoint until the issue is resolved.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41460

Affected Products

Socialengine