SQL Injection in highwarden Super Store Finder by highwarden
CVE-2026-108541
5.3MEDIUM
What is CVE-2026-108541?
A vulnerability exists in highwarden Super Store Finder versions up to 3.8, specifically in the argument processing within the /products/superstorefinder/index.php file. This flaw allows an attacker to manipulate lat/lng parameters, leading to SQL injection, which can be exploited remotely. The vulnerability was disclosed publicly and can be exploited if unpatched. Users are encouraged to upgrade to version 3.9 or later to mitigate this risk, as the vendor has promptly addressed the issue after being informed.
Affected Version(s)
Super Store Finder 3.0
Super Store Finder 3.1
Super Store Finder 3.2
