PatchSiren cyber security CVE debrief
CVE-2026-42381 FunnelKit CVE debrief
CVE-2026-42381 is a critical unauthenticated SQL injection vulnerability in Funnel Builder by FunnelKit versions <= 3.15.0.1. The vulnerability has a CVSS score of 9.3 and is considered critical. It was published on 2026-06-15T21:16:53.990Z and modified on 2026-06-15T21:24:32.790Z.
- Vendor
- FunnelKit
- Product
- Funnel Builder by FunnelKit
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-15
- Original CVE updated
- 2026-06-15
- Advisory published
- 2026-06-15
- Advisory updated
- 2026-06-15
Who should care
Users of Funnel Builder by FunnelKit versions <= 3.15.0.1 should be aware of this vulnerability and take necessary actions to mitigate it.
Technical summary
The vulnerability is an unauthenticated SQL injection vulnerability in Funnel Builder by FunnelKit versions <= 3.15.0.1. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L.
Defensive priority
high
Recommended defensive actions
- Update Funnel Builder by FunnelKit to a version greater than 3.15.0.1.
- Refer to resourceLinkAnnotations for additional mitigation or vendor references: [ref-4].
Evidence notes
The vendor and product information is currently unknown. The CVE record is available at [cve-org] and the NVD detail is available at [nvd].
Official resources
-
CVE-2026-42381 CVE record
CVE.org
-
CVE-2026-42381 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
This CVE debrief was generated based on the provided source corpus and official links.