PT-2026-43652 · WordPress · Tainacan

Hhhai

·

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-42740

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Tainacan versions prior to 1.0.4
Description Tainacan is subject to Blind SQL Injection, which occurs when an application fails to properly neutralize special elements used in an SQL command, allowing an attacker to infer data by observing the application's response to specific queries.
Recommendations Update to a version later than 1.0.3.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42740

Affected Products

Tainacan