CRITICAL
9.8 CVE-2026-79570 Published 8 Sept 2026
mfish-nocode-pro SQL Injection
Worried this affects one of your servers?
mfish-nocode-pro v1.0.0 contains a SQL injection vulnerability.
Attackers can exploit this by sending a crafted SQL statement to the /sys/dbConnect/data endpoint.
This allows unauthorized access to sensitive database information.
Reference: CVE-2026-79570 on NVD
← Back to Security News