
CVE-2026-77137 The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary SQL through a… https://www.cve.org/CVERecord?id=CVE-2026-77137
Post summary
The snippet identifies a SQL injection vulnerability in an extension, noting improper input sanitization, but provides no PoC, exploit, patch, or active exploitation report.

