CRITICAL
9.8 CVE-2026-88395 Published 5 Oct 2026
GouGuOA SQL Injection Vulnerability in Message Rubbish Endpoint
Worried this affects your website?
GouGuOA versions 6.0.5 and earlier are affected by a SQL Injection vulnerability.
The flaw exists in the /home/message/rubbish endpoint, where the keywords parameter is not properly sanitized.
An attacker could exploit this to inject arbitrary SQL queries.
Reference: CVE-2026-88395 on NVD
← Back to Security News