cleantalk
Vulnerabilities and Security Researches

Wishlist, CVE-2025-26915

CVE, Research URL

CVE-2025-26915

Application

Wishlist

Published on
Feb 25, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist allows SQL Injection. This issue affects Wishlist: from n/a through 1.0.41.
Affected versions
Min -, max 1.0.42.
Status
vulnerable