CVE-2026-108799 | jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261 Password Recovery Mail Endpoint PublicController.class.php sendFindPwdMail email sql injection
A vulnerability was found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. It has been classified as critical. Impacted is the function PublicController::sendFindPwdMail of the file Admin/Home/Controller/PublicController.class.php of the component Password Recovery Mail Endpoint. This manipulation of the argument email causes sql injection.
This vulnerability is registered as CVE-2026-108799. Remote exploitation of the attack is possible. Furthermore, an exploit is available.VulDB Recent EntriesRead More