OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-42414

HIGH · CVSS 8.5

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

ListingPro versions up to 2.9.12 are vulnerable to a SQL injection flaw that allows attackers to manipulate database queries, potentially leading to unauthorized access to sensitive data. Organizations using these affected versions should prioritize patching this vulnerability to mitigate the risk of data breaches and maintain the integrity of their systems.

CVE
CVE-2026-42414
Severity
HIGH
CVSS
8.5
EPSS
N/A

Original NVD Description

Subscriber SQL Injection in ListingPro <= 2.9.12 versions.