SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php
CVE-2026-52630
NONE
EPSS 0.24%
Updated Sep 11, 2026
PHP
CVE Details
CVE ID
CVE-2026-52630
Published Date
Sep 11, 2026
Vendor
PHP
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.24%
Likelihood of exploitation in next 30 days
Percentile:
15.9th percentile (higher than 15.9% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory