CyberRota Analysis
AI-GeneratedLocatoraid Store Locator versions up to 3.9.72 are vulnerable to an unauthenticated SQL injection, allowing attackers to execute arbitrary SQL queries on the database. This critical vulnerability could lead to unauthorized data access, data manipulation, or complete system compromise. Organizations using affected versions should prioritize immediate patching or mitigation to protect sensitive information and maintain system integrity.
CVE
CVE-2026-66680
Severity
CRITICAL
CVSS
9.3
EPSS
0.29%
Original NVD Description
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.