pdnuclei-bot@pdnuclei_botDisclosure
The tweet announces CVE-2026-40887 as a critical SQL injection in Vendure Core, offering a link to a library entry but no PoC, exploit code, or evidence of active exploitation.
N45HT@N45HTOfficialDisclosure
The post announces a new SQL injection vulnerability (CVE-2026-40887) in @vendure/core, providing links to official advisories, but does not contain PoC, exploit code, active exploitation evidence, or patch information.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The CVE is an unauthenticated SQL injection affecting Vendure Shop API prior to version 2.3.4; the announcement merely identifies the vulnerability without providing exploitation or mitigation details.
0day Signal@0dayPublishingDisclosure
A new unauthenticated SQL injection vulnerability (CVE-2026-40887) in Vendure's Shop API that exploits the languageCode parameter is disclosed, with technical specifics and a link for further details; no exploit code or active exploitation is reported.
PulsePatch.io@pulsepatchioPatch
The post alerts to a new SQL injection vulnerability in Vendure Core, prompting input‑validation checks and highlighting that a patch is forthcoming.