OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-39747

HIGH · CVSS 8.5

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Woffice versions up to 5.4.35 are vulnerable to a SQL injection attack that allows unauthorized access to the database, potentially leading to data exfiltration or manipulation. Organizations using this version of Woffice should prioritize patching to mitigate the risk of exploitation, especially those handling sensitive information.

CVE
CVE-2026-39747
Severity
HIGH
CVSS
8.5
EPSS
N/A
Office

Original NVD Description

Subscriber SQL Injection in Woffice <= 5.4.35 versions.