CVE-2026-31858: CraftCMS's `ElementSearchController` Affected by Blind SQL Injection
Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to ElementIndexesController in CVE-2026-25495. The exact same SQL injection vulnerability (including criteria[orderBy], the original advisory vector) works on this controller because the fix was never applied to it. Any authenticated control panel user (no admin required) can inject arbitrary SQL via criteria[where], criteria[orderBy], or other query properties, and extract the full database contents via boolean-based blind injection. Users should update to the patched 5.9.9 release to mitigate the issue.
Other sources
The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to ElementIndexesController in GHSA-2453-mppf-46cj.
The exact same SQL injection vulnerability (including criteria[orderBy], the original advisory vector) works on this controller because the fix was never applied to it.
Any authenticated control panel user (no admin required) can inject arbitrary SQL via criteria[where], criteria[orderBy], or other query properties, and extract the full database contents via boolean-based blind injection.
Users should update to the patched 5.9.9 release to mitigate the issue.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31858?
CVE-2026-31858 is classified as a moderate severity SQL injection vulnerability.
How do I fix CVE-2026-31858?
To fix CVE-2026-31858, update the Craft CMS package to version 5.9.9 or later.
What causes CVE-2026-31858?
CVE-2026-31858 is caused by the missing unset() protection in the ElementSearchController::actionSearch() endpoint.
What versions are affected by CVE-2026-31858?
CVE-2026-31858 affects Craft CMS versions from 5.0.0-RC1 up to 5.9.8.
Is CVE-2026-31858 a known vulnerability?
Yes, CVE-2026-31858 is a known vulnerability that has been publicly disclosed.