SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57726

CRITICAL · CVSS 9.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in Themeum Kirki allows for Blind SQL Injection due to improper neutralization of special elements in SQL commands, potentially enabling attackers to manipulate database queries and access sensitive information. Organizations using Kirki versions up to 6.0.12 should prioritize patching this critical security flaw to mitigate the risk of unauthorized data exposure and exploitation. Immediate action is essential for those managing applications that rely on this library.

CVE
CVE-2026-57726
Severity
CRITICAL
CVSS
9.3
EPSS
0.28%

Original NVD Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.