What is CVE-2026-59527?
An unauthenticated SQL Injection vulnerability was discovered in MapSVG plugin versions up to 8.14.0. This flaw could allow a remote attacker to read the database, immediate update to the latest version is recommended.
Azərbaycanca: MapSVG plaginin 8.14.0 və əvvəlki versiyalarında autentifikasiya tələb etməyən SQL Injection zəifliyi aşkarlanıb. Bu boşluq uzaqdan hücum edən şəxsə verilənlər bazasını oxumağa imkan verə bilər, dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which plugin and versions are affected by CVE-2026-59527?
This SQL Injection vulnerability affects the MapSVG plugin versions up to 8.14.0.
What capability could CVE-2026-59527 provide to a remote attacker?
This flaw could allow a remote attacker to read the database without authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.