๐Ÿ” CVE Alert

CVE-2026-92692

UNKNOWN 0.0

Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Sulu/Component/Content/SmartContent/QueryBuilder.php that concatenates category identifiers from the public categories query parameter into a JCR-SQL2 WHERE clause without numeric validation. On a public page containing a category-filtered Smart Content block, an unauthenticated attacker can alter query conditions to infer or enumerate content-repository nodes, including unpublished content, or submit malformed and expensive query fragments that degrade availability; this path does not modify repository data. This issue is fixed in versions 2.6.25 and 3.0.8.

CWE CWE-89
Vendor sulu
Product sulu
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for sulu sulu

Be the first to know when new unknown vulnerabilities affecting sulu sulu are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

sulu / sulu
< 2.6.25 >= 3.0.0, < 3.0.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sulu/sulu/security/advisories/GHSA-jg26-q8hg-3pq4 github.com: https://github.com/sulu/sulu/commit/d19c01487af8c3de2fb3aa145856707a6367392c github.com: https://github.com/sulu/sulu/releases/tag/2.6.25 github.com: https://github.com/sulu/sulu/releases/tag/3.0.8