OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-42415

CRITICAL · CVSS 9.3

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Porto Theme versions up to 3.9.3 are vulnerable to an unauthenticated SQL injection, allowing attackers to execute arbitrary SQL queries and potentially gain unauthorized access to sensitive data. This critical vulnerability poses a significant risk to any website utilizing the affected theme, making it imperative for developers and site administrators to prioritize immediate updates or mitigations. Organizations relying on this theme should act swiftly to safeguard their systems against potential exploitation.

CVE
CVE-2026-42415
Severity
CRITICAL
CVSS
9.3
EPSS
N/A

Original NVD Description

Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.