Smart Content QueryBuilder Vulnerability in Sulu PHP CMS
CVE-2026-92692

6.9MEDIUM

Key Information:

Vendor

Sulu

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-92692?

The Sulu CMS is affected by a vulnerability in the Smart Content QueryBuilder, where category identifiers from the public categories query parameter are concatenated into a JCR-SQL2 WHERE clause without appropriate numeric validation. An unauthenticated attacker can exploit this flaw on public pages with category-filtered Smart Content blocks to manipulate query conditions, enabling them to infer or enumerate content-repository nodes, which may include unpublished content. Additionally, attackers could submit malformed queries, leading to performance degradation of the application without altering the repository data. This vulnerability has been resolved in versions 2.6.25 and 3.0.8.

Affected Version(s)

sulu < 2.6.25 < 2.6.25

sulu >= 3.0.0, < 3.0.8 < 3.0.0, 3.0.8

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.