
CVE-2026-62059: Ultimate Member <= 2.13.1 stores member directory search-field identifiers without sanitization, and those identifiers are concatenated raw into the SQL of every directory search - an administrator-planted, second-order (stored) SQL injection. #poc #0day #news #New https://github.com/Hassham1/CVE-2026-62059-ultimate-member-sqli-poc
