CVE-2026-27413Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (5 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-19: 5PoC Mentioned / Linked · 2026-03-19: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-03-19: 503-19
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27413 Blind SQL Injection in Cozmoslabs Profile Builder Pro Through 3.13.9 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27413

    Post summary

    The text announces a blind SQL injection vulnerability in Cozmoslabs Profile Builder Pro up to version 3.13.9, providing a link to further detail without additional exploitation or mitigation information.

    0000038
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27413: CRITICAL] Cozmoslabs Profile Builder Pro is vulnerable to SQL Injection, allowing attackers to execute Blind SQL Injection. Update to version 3.14 to patch the vulnerability.#cve,CVE-2026-27413,#cybersecurity https://cvefind.com/CVE-2026-27413

    Post summary

    CVE-2026-27413 is a critical blind SQL injection in Cozmoslabs Profile Builder Pro; users should update to version 3.14 to apply the patch.

    0000052
    604 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27413 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This i… https://www.cve.org/CVERecord?id=CVE-2026-27413

    Post summary

    The tweet announces CVE-2026-27413 as a blind SQL injection in Cozmoslabs Profile Builder Pro, but provides only basic vulnerability details without PoC, exploit, or patch information.

    0000077
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27413 - Critical Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile ... https://www.thehackerwire.com/vulnerability/CVE-2026-27413/ https://t.co/t4vSMOeqXj

    Post summary

    A new critical SQL injection vulnerability (CVE-2026-27413) affecting Cozmoslabs Profile Builder Pro has been publicly disclosed, with specific technical details provided, but no PoC, exploit, patch, or active exploitation information is present.

    0000032
    138 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-27413: WordPress Profile Builder Pro pl... Blind SQLi in Profile Builder Pro with CVSS 9.3 and zero auth required - WordPress admins better patch before attackers... https://zerodaysignal.com/vulnerability/CVE-2026-27413 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new blind SQLi vulnerability (CVE‑2026‑27413) is disclosed for WordPress Profile Builder Pro, rated CVSS 9.3 with no authentication required; patching is advised.

    0000046
    155 followersView on X

Explore more