OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-41555

CRITICAL · CVSS 9.3

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An unauthenticated SQL injection vulnerability exists in the Newsletter Subscription Form, specifically affecting versions 1.5.9 and earlier. This flaw allows attackers to manipulate database queries, potentially leading to unauthorized data access or data compromise. Organizations using affected versions should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-41555
Severity
CRITICAL
CVSS
9.3
EPSS
N/A

Original NVD Description

Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.