SQL Injection Vulnerability in King-Theme Lumise Product Designer
CVE-2026-25371
9.3CRITICAL
What is CVE-2026-25371?
The Lumise Product Designer by King-Theme is vulnerable to an SQL Injection flaw that allows for unauthorized access to the database through poorly sanitized inputs in SQL queries. This vulnerability can be exploited to manipulate database commands, leading to potential data breaches or unauthorized information retrieval. It affects versions prior to 2.0.9 and emphasizes the need for securing input data to prevent such attacks.
Affected Version(s)
Lumise Product Designer 0 <= 2.0.9
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jarno Vos (jrn5151) | Patchstack Bug Bounty Program