CRITICAL 9.8 CVE-2026-79570 Published 8 Sept 2026

mfish-nocode-pro SQL Injection

Worried this affects one of your servers?

mfish-nocode-pro v1.0.0 contains a SQL injection vulnerability.

Attackers can exploit this by sending a crafted SQL statement to the /sys/dbConnect/data endpoint.

This allows unauthorized access to sensitive database information.

Reference: CVE-2026-79570 on NVD

← Back to Security News