CRITICAL
9.8 CVE-2026-52630 Published 11 Sept 2026
Woltlab WCF SQL Injection Vulnerability
Worried this affects one of your servers?
Woltlab WCF, a forum software, is affected by an SQL Injection vulnerability.
Woltlab WCF versions 6.2.4 and earlier are vulnerable. An attacker can exploit this by manipulating user options in UserEditor.class.php and the update action in UserAction.class.php.
Reference: CVE-2026-52630 on NVD
← Back to Security News