CVE-2026-4508 | PbootCMS up to 3.2.12 Member Login MemberController.php checkUsername sql injection (EUVD-2026-13931)
A vulnerability, which was classified as critical, has been found in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the argument Username leads to sql injection.
This vulnerability is listed as CVE-2026-4508. The attack may be initiated remotely. In addition, an exploit is available.