CVE-2026-36458Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-12: 4Technical Details · 2026-05-12: 305-12
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets1 URL
By indicator
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-36458 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text lists basic CVE information and severity metrics but provides no additional context such as proof of concept, exploitation activity, or remediation.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-36458 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory ChestnutCMS v1.5.10 has a SQL injection vulnerability.

    Post summary

    ChestnutCMS v1.5.10 contains a critical SQL injection (CVE-2026-36458) with a CVSS score of 9.8 and a critical advisory.

    1000037
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-36458 (CVSS 9.8) — multiple products. CVE: CVE-2026-36458 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text is a critical advisory for CVE-2026-36458, indicating a high severity score but providing no information about PoC, exploits, active use, or remediation.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-36458-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    A link to a research advisory for CVE-2026-36458 is shared, but the text contains no explicit evidence of PoC, exploit code, active exploitation, patch details, or technical specifics.

    0000021
    210 followersView on X

Explore more