← לוח פגיעויות

CVE-2026-79322

גבוהה 8.6

תיאור (מקור, אנגלית)

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view.

מדדים

CVSS 3.1
8.6 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-5/10/2026
CWE
CWE-89

מוצרים מושפעים

mageplaza: mageplaza blog

קישורים