CRITICAL 9.8 CVE-2026-88395 Published 5 Oct 2026

GouGuOA SQL Injection Vulnerability in Message Rubbish Endpoint

Worried this affects your website?

GouGuOA versions 6.0.5 and earlier are affected by a SQL Injection vulnerability.

The flaw exists in the /home/message/rubbish endpoint, where the keywords parameter is not properly sanitized.

An attacker could exploit this to inject arbitrary SQL queries.

Reference: CVE-2026-88395 on NVD

← Back to Security News