CVE-2026-88756
21.09.2026, 22:16
Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate).Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.