CVE-2026-105149 is a SQL injection vulnerability in mooSocial up to 3.2.4, located in the /stores/all-products file. The issue can be triggered by manipulating the rating argument, allowing for remote exploitation. The exploit has been publicly released, increasing the urgency for defenders to verify exposure and prioritize remediation. Defenders should assess the risk of remote exploitation and implement [truncated]
CVE-2018-25371 documents a blind SQL injection vulnerability in mooSocial Store Plugin version 2.6. The vulnerability exists in the product parameter used within URL rewrite functionality, allowing unauthenticated attackers to inject malicious SQL code. Successful exploitation enables database manipulation through boolean-based blind, time-based blind, or stacked query techniques, potentially leading to u [truncated]