CVE-2026-40797General

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection. This issue affects WebinarIgnition: from n/a through 4.08.253.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-05); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-05: 2Mentions · 2026-05-12: 2Mentions · 2026-05-17: 1Patch / Workaround · 2026-05-17: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-17: 105-0505-1205-17
Signal classification3 categories
General
360.0%
Disclosure
120.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure1General1
2026-05-122
General2
2026-05-171
Patch1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-40797 CVSS: 9.3 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L Severity: CRITICAL Status: Critical advisory

    Post summary

    The note lists a CVE with its CVSS score and severity designation, but offers no further context about exploits, patches, or real-world activity.

    1000027
    210 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A critical SQL Injection vulnerability (CVE-2026-40797) affects WebinarIgnition through version 4.08.253. If you use this software, update promptly to prevent potential data breaches. ADK Cyber can help ensure your defenses are up-to-date. #Cybersecurity

    Post summary

    The post announces CVE-2026-40797, a critical SQL Injection affecting WebinarIgnition, and urges users to apply updates to mitigate potential data breaches.

    0000061
    80 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-40797-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post only shares a link and hashtags, offering no substantive details about the CVE.

    0000022
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40797 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection. Thi… https://www.cve.org/CVERecord?id=CVE-2026-40797 ----- Traducción: CVE-2026-40797 Fal… http://infoflow.cloud`

    Post summary

    The text discloses a blind SQL injection vulnerability (CVE‑2026‑40797) in Saleswonder LLC WebinarIgnition, detailing the error type but providing no PoC, exploit, or mitigation.

    0000028
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40797 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection. Thi… https://www.cve.org/CVERecord?id=CVE-2026-40797

    Post summary

    The text merely references CVE-2026-40797 and notes it is a blind SQL injection flaw in WebinarIgnition, but lacks detailed information on exploitation or mitigation.

    00000137
    57.4K followersView on X

Explore more