GHSA-38cq-4qpv-62wfMediumCVSS 5.3

Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the...

Published
September 22, 2026
Last Modified
September 24, 2026

🔗 CVE IDs covered (1)

📋 Description

Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate).

🔗 References (4)