CVE-2026-40529
CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th
CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface.
| Vendor | kanata limited |
| Product | cms alaya |
| Published | Apr 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for kanata limited cms alaya
Be the first to know when new medium vulnerabilities affecting kanata limited cms alaya are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L Affected Versions
KANATA Limited / CMS ALAYA
7.4.1.4 and earlier