CVE-2026-7435Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic endpoint to execute arbitrary SQL statements, leading to unauthorized database access, data disclosure, authentication bypass, data modification, or complete database compromise.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-30); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-30: 2Mentions · 2026-05-01: 1Technical Details · 2026-04-30: 2Technical Details · 2026-05-01: 104-3005-01
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-302
Disclosure1General1
2026-05-011
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7435 SQL Injection in SSCMS v7.4.0 stl:sqlContent Tag Dynamic Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7435 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A newly disclosed SQL injection vulnerability (CVE-2026-7435) affecting SSCMS v7.4.0's stl:sqlContent Tag dynamic endpoint has been reported, but no PoC, exploit, or patch details are provided.

    0000047
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7435 SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameter… https://www.cve.org/CVERecord?id=CVE-2026-7435 ----- Traducción: CVE-2026-7435 SSC… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-7435 as a SQL injection in SSCMS v7.4.0, detailing the vulnerable tag and attribute, but offers no PoC, exploitation details, or mitigation information.

    0000017
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7435 SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameter… https://www.cve.org/CVERecord?id=CVE-2026-7435

    Post summary

    The text announces a SQL injection vulnerability in SSCMS v7.4.0’s stl:sqlContent tag and links to the CVE record, but does not provide any PoC, exploit details, or patch information.

    00000146
    57.4K followersView on X

Explore more