OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-39771

HIGH · CVSS 8.5

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Buddyboss Platform versions up to 3.1.0 are vulnerable to a SQL Injection attack, which could allow an attacker to manipulate database queries and potentially access sensitive information. This high-severity vulnerability poses a significant risk to any organization using affected versions, particularly those managing user subscriptions or sensitive data. Organizations utilizing the Buddyboss Platform should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-39771
Severity
HIGH
CVSS
8.5
EPSS
N/A

Original NVD Description

Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions.