CVE-2026-4508General

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-21); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-27: 1Technical Details · 2026-03-21: 103-2103-27
Signal classification1 categories
General
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-212
General2
2026-03-271
General1
Full discourse3 posts
  • IntegSec@integ_sec
    General

    CVE-2026-4508: PbootCMS Member Login SQL Injection - What It Means for Your Business and How to Respond https://hubs.li/Q048DGXf0

    Post summary

    The supplied text only offers a headline and a link, lacking any concrete evidence of PoC, exploitation, patching, or technical details.

    0000030
    31 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4508 A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the… https://www.cve.org/CVERecord?id=CVE-2026-4508

    Post summary

    The text provides a concise CVE reference and technical details but does not indicate PoC, exploit, or patch, classifying it as a general CVE notice.

    00000132
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4508 - n/a - PbootCMS - https://www.redpacketsecurity.com/cve-alert-cve-2026-4508-n-a-pbootcms/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4508 #n-a #pbootcms

    Post summary

    The post announces a CVE alert for CVE-2026-4508 on PbootCMS but offers no technical details, patch information, or evidence of exploitation.

    0000082
    3.6K followersView on X

Explore more