Threats Tagged 'cve-2026-50636'
View all threats tagged with 'cve-2026-50636'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-50636'
Click on any threat for detailed analysis and mitigation recommendations
LimeSurvey has a SQL Injection issue (CVE-2026-50636)CVE-2026-50636 0 LimeSurvey version 7.0.0-beta1 contains a SQL injection vulnerability in its RemoteControl API methods invite_participants and remind_participants. These methods pass user-supplied token-ID arrays directly into an SQL query without proper parameterization or input validation, enabling an authenticated attacker with tokens/update permission to perform SQL injection. The vulnerability allows execution of stacked queries due to PDO emulated prepared statements and enabled MySQL multi-statements. Exploitation can lead to arbitrary data read and write, including administrator password hash theft and database destruction. The RemoteControl interface must be enabled for exploitation, which is not enabled by default. Join the discussion | GCVE Database | 06/09/2026, 18:31:04 UTC Added: 07/31/2026, 21:29:18 UTC |
Showing 1 to 1 of 1 result