CVE-2026-88397

ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list endpoint GET /admin/User/getUsers via the gid parameter.

  • Published Oct 5, 2026
  • Not yet scored

CVE-2026-88397 at the National Vulnerability Database