CyberRota Analysis
AI-GeneratedWeb Directory Free versions up to 1.7.13 are vulnerable to an unauthenticated SQL injection, allowing attackers to execute arbitrary SQL commands on the database. This critical vulnerability could lead to data leakage, unauthorized access, or complete system compromise. Organizations using this software should prioritize immediate remediation to mitigate potential exploitation risks.
CVE
CVE-2026-28142
Severity
CRITICAL
CVSS
9.3
EPSS
0.29%
Original NVD Description
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.