Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
CVE-2026-81287 at the National Vulnerability Database