CVE-2026-6982Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file server/Application/Api/Controller/PageController.class.PHP of the component API Page Sort Endpoint. Executing a manipulation of the argument pages can lead to sql injection. The attack may be launched remotely. Upgrading to version 3.8.1 addresses this issue. It is suggested to upgrade the affected component. According to the researcher, "[t]he vendor explicitly stated they will not backport patches to the older affected versions."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-25: 2Technical Details · 2026-04-25: 104-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-6982 A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file server/Application/A… https://www.cve.org/CVERecord?id=CVE-2026-6982

    Post summary

    The text cites CVE-2026-6982 and notes its impact on star7th ShowDoc versions, but provides no detailed technical information or evidence of exploitation.

    0000044
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6982 SQL Injection in star7th ShowDoc API Page Sort Endpoint Versions Up to 3.8.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6982

    Post summary

    The text announces a SQL Injection flaw in the ShowDoc API Page Sort endpoint (versions ≤ 3.8.0), providing technical details but no evidence of exploitation, PoC, or patch.

    0000041
    4.0K followersView on X

Explore more