PT-2026-50671 · Ubb Systems · Ubb.Threads

Kamil Szczurowski

+1

·

Published

2026-06-18

·

Updated

2026-06-18

·

CVE-2026-54222

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions UBB.threads version 7.7.5
Description Insufficient input sanitization in the Members in Control Panel allows attackers to interact with the underlying database via Blind SQL Injection. This technique involves sending queries that the database answers with a boolean (true/false) or a time delay, enabling the extraction of sensitive information such as user credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54222

Affected Products

Ubb.Threads