PatchSiren

Wgcloud CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Wgcloud CVE published 2026-07-21

CVE-2026-52472

A SQL injection vulnerability exists in Wgcloud version 3.6.4. This vulnerability allows a remote attacker to escalate privileges via the PortInfoMapper.xml file. The Common Vulnerabilities and Exposures (CVE) score for this vulnerability is 9.8, indicating a critical severity level. The vulnerability is caused by a lack of proper input validation in the PortInfoMapper.xml file, allowing an attacker to in [truncated]