HIGHVulnerability
CVE-2026-73331
CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slug value containing SQL syntax that the database backend evaluates as part of an inadequately parameterized query. Attackers can supply malicious slug payloads using boolean- or union-style blind SQL injection techniques to extract sensitive data from the underlying SQLite database, including administrative credentials and configuration values stored in application tables.
Properties
- severity
- HIGH
- score
- 7.1
- epss_score
- 0.00264
- cve_id
- CVE-2026-73331
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- published_at
- 2026-08-12T20:17:55.340
- last_modified
- 2026-09-08T20:32:39.347
- epss_percentile
- 0.18145
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Explore deeper with Ninja Signal's threat intelligence graph