SocialEngine versions 7.8.0 and prior have a blind server-side request forgery vulnerability that could allow unauthorized actions.
Claims
SocialEngine versions 7.8.0 and prior have a blind server-side request forgery vulnerability that could allow unauthorized actions.
Parent: CybersecurityEntity: SocialEngineImpact: negativeDate: Apr 23, 2026Target: SocialEngine's security practices
SocialEngine versions 7.8.0 and prior have a SQL injection vulnerability that could allow unauthorized access to database information.
Parent: CybersecurityEntity: SocialEngineImpact: negativeDate: Apr 23, 2026Target: SocialEngine's security practices
Source posts
๐จ EUVD-2026-25224
๐ Score: 9.3/10 (CVSS v3.1)
๐ฆ Product: SocialEngine
๐ข Vendor: SocialEngine
๐
Updated: 2026-04-23
๐ SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. An unauth...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25224
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25226
๐ Score: 6.3/10 (CVSS v3.1)
๐ฆ Product: SocialEngine
๐ข Vendor: SocialEngine
๐
Updated: 2026-04-23
๐ SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is not sanitized before being used to construct outbou...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25226
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability