Skip to main content
Loading…
    CVE-2026-28562 — wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted identifiers. Attackers — CVE Database · The Intelligence Room