Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
CVE-2026-81286 at the National Vulnerability Database