Administrator SQL Injection in Newsletters <= 4.18 versions.
CVE-2026-66619 at the National Vulnerability Database