PatchSiren

WoltLab CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review WoltLab CVE published 2026-09-11

CVE-2026-52630

A SQL Injection vulnerability exists in Woltlab WCF versions 6.2.4 and earlier. This issue allows a remote attacker to update user options via UserEditor.class.php and the update action in UserAction.class.php. Defenders should assess exposure, particularly those managing user accounts or systems using Woltlab WCF. The vulnerability's impact on confidentiality, integrity, or availability requires verifica [truncated]

Review WoltLab CVE published 2026-09-11

CVE-2026-79362

Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code. This vulnerability allows for potential code execution, impacting the securi [truncated]