Showing 1 vulnerability on this page for XATABoost CMS

Signals CISA KEV Ransomware Nuclei
xataboost vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

XATABoost CMS 1.0.0 SQL Injection via news.php

XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information.

CWE-89Apr 29, 2026
CVSS8.8v4.0EPSS0.323%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX