Home

Description

SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inject arbitrary SQL commands, potentially gaining full control over the database. This issue affects SOPlanning version 1.55 and below.

PUBLISHED Reserved 2026-04-14 | Published 2026-06-01 | Updated 2026-06-01 | Assigner CERT-PL




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

Any version
affected

Credits

Łukasz Jaworski finder

References

cert.pl/en/posts/2026/06/CVE-2026-40543 third-party-advisory

www.soplanning.org/en/ product

cve.org (CVE-2026-40546)

nvd.nist.gov (CVE-2026-40546)

Download JSON