CVE-2026-88416: SQL Injection
Published Sep 22, 2026
·Updated
MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature.
Affected Software
1 affected component
Mcms MCMS>=6.1.1<=6.2.1
Event History
Sep 22, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
What feature must be reachable for this issue to be exploitable?
The vulnerable functionality is the custom model/form import feature. Deployments that do not expose or use that feature are not described as affected through another path.
2
Which versions are identified as affected?
MCMS versions 6.1.1 through 6.2.1 are identified as affected.