CVE-2026-96604 | SoftNews Media Group DataLife Engine 18.0 Search search.php strip_data story sql injection

SecurityVulns

A vulnerability has been found in SoftNews Media Group DataLife Engine 18.0 and classified as critical. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql injection.

This vulnerability is documented as CVE-2026-96604. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More