CRITICAL 9.8 CVE-2026-52630 Published 11 Sept 2026

Woltlab WCF SQL Injection Vulnerability

Worried this affects one of your servers?

Woltlab WCF, a forum software, is affected by an SQL Injection vulnerability.

Woltlab WCF versions 6.2.4 and earlier are vulnerable. An attacker can exploit this by manipulating user options in UserEditor.class.php and the update action in UserAction.class.php.

Reference: CVE-2026-52630 on NVD

← Back to Security News