← Back to search

CVE-2026-95601

9.3 CRITICAL

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
This flaw allows unauthenticated attackers to inject SQL commands, potentially leading to data theft or manipulation.
Exploitability
Exploitation is relatively easy as it requires no authentication, and the SQL injection can be triggered through the Product Filter feature.
Blast radius
If exploited, the attacker could access sensitive data or manipulate the database, impacting the integrity and confidentiality of the application's data.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to WBW Product Filter version 3.1.8 or later.
rcesql-injectionwebunauthenticated

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

Weaknesses

CWE-89

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.