CyberRota Analysis
AI-GeneratedWoffice versions up to 5.4.35 are vulnerable to a SQL injection attack that allows unauthorized access to the database, potentially leading to data exfiltration or manipulation. Organizations using this version of Woffice should prioritize patching to mitigate the risk of exploitation, especially those handling sensitive information.
CVE
CVE-2026-39747
Severity
HIGH
CVSS
8.5
EPSS
N/A
Office
Original NVD Description
Subscriber SQL Injection in Woffice <= 5.4.35 versions.