SQL Injection in highwarden Super Store Finder by highwarden
CVE-2026-108541

5.3MEDIUM

Key Information:

Vendor

Highwarden

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108541?

A vulnerability exists in highwarden Super Store Finder versions up to 3.8, specifically in the argument processing within the /products/superstorefinder/index.php file. This flaw allows an attacker to manipulate lat/lng parameters, leading to SQL injection, which can be exploited remotely. The vulnerability was disclosed publicly and can be exploited if unpatched. Users are encouraged to upgrade to version 3.9 or later to mitigate this risk, as the vendor has promptly addressed the issue after being informed.

Affected Version(s)

Super Store Finder 3.0

Super Store Finder 3.1

Super Store Finder 3.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

skalvin (VulDB User)
VulDB CNA Team
.