🔐 CVE Alert

CVE-2026-54222

UNKNOWN 0.0

Blind SQL Injection in UBB.threads

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to interact with the underlying database. Due to insufficient input sanitization, an attacker can extract sensitive information, such as user credentials, by manipulating SQL queries through time-based or boolean-based techniques. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions.

CWE CWE-89
Vendor ubb systems
Product ubb.threads
Published Jun 18, 2026
Last Updated Jun 18, 2026
Stay Ahead of the Next One

Get instant alerts for ubb systems ubb.threads

Be the first to know when new unknown vulnerabilities affecting ubb systems ubb.threads are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

UBB Systems / UBB.threads
0 ≤ 7.7.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
ubbcentral.com: https://www.ubbcentral.com/ cert.pl: https://cert.pl/en/posts/2026/06/CVE-2026-54219

Credits

Kamil Szczurowski (Securitum) Michał Wnękowicz (Securitum)