CVE-2026-72558 | CiviCRM up to 6.18.alpha1 Contact Search sql injection
A vulnerability has been found in CiviCRM up to 6.18.alpha1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Contact Search. This manipulation causes sql injection.
The identification of this vulnerability is CVE-2026-72558. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More