PT-2026-45359 · Unknown · Soplanning

Łukasz Jaworski

·

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-40546

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SOPlanning versions prior to 1.56
Description SQL Injection allows an attacker with low privileges to inject arbitrary SQL commands, which could lead to full control over the database.
Recommendations Update to a version newer than 1.55.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40546

Affected Products

Soplanning