SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover.
CVE-2026-79387
NONE
EPSS 0.32%
Updated Sep 10, 2026
SQL
CVE Details
CVE ID
CVE-2026-79387
Published Date
Sep 10, 2026
Vendor
SQL
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.32%
Likelihood of exploitation in next 30 days
Percentile:
25.2th percentile (higher than 25.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory