Loading market data...
← Back to CVE feed

CVE-2026-4776

HIGH CVSS 7.1 View on NVD ↗

Description

An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Published: May 29, 2026 08:16 UTC Modified: May 29, 2026 15:39 UTC