Smart Content QueryBuilder Vulnerability in Sulu PHP CMS
CVE-2026-92692
What is CVE-2026-92692?
The Sulu CMS is affected by a vulnerability in the Smart Content QueryBuilder, where category identifiers from the public categories query parameter are concatenated into a JCR-SQL2 WHERE clause without appropriate numeric validation. An unauthenticated attacker can exploit this flaw on public pages with category-filtered Smart Content blocks to manipulate query conditions, enabling them to infer or enumerate content-repository nodes, which may include unpublished content. Additionally, attackers could submit malformed queries, leading to performance degradation of the application without altering the repository data. This vulnerability has been resolved in versions 2.6.25 and 3.0.8.
Affected Version(s)
sulu < 2.6.25 < 2.6.25
sulu >= 3.0.0, < 3.0.8 < 3.0.0, 3.0.8
