PatchSiren cyber security CVE debrief
CVE-2026-54819 Webilia Inc. CVE debrief
A critical SQL injection vulnerability, known as CVE-2026-54819, has been identified in the Listdom plugin, affecting versions from n/a through 5.4.0. This vulnerability, with a CVSS score of 9.3, allows attackers to perform blind SQL injection attacks. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Listdom plugin are urged to take immediate action to mitigate this vulnerability.
- Vendor
- Webilia Inc.
- Product
- Listdom
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Administrators and users of the Listdom plugin, particularly those using versions up to 5.4.0, should be aware of this critical vulnerability and take necessary actions to secure their installations.
Technical summary
The CVE-2026-54819 vulnerability is an improper neutralization of special elements used in an SQL command, also known as SQL injection. This vulnerability allows attackers to inject malicious SQL code, potentially leading to unauthorized access to sensitive data. The vulnerability has been classified as critical with a CVSS score of 9.3. The affected product is Listdom, and the vulnerability affects versions from n/a through 5.4.0.
Defensive priority
high
Recommended defensive actions
- Update the Listdom plugin to a version beyond 5.4.0 immediately.
- Restrict access to the Listdom plugin to only trusted users and networks.
- Implement a web application firewall (WAF) to detect and prevent SQL injection attacks.
- Regularly review and update plugins and software to ensure the latest security patches are applied.
- Monitor plugin and system logs for suspicious activity indicative of SQL injection attempts.
Evidence notes
The information provided is based on data from official sources, including the CVE.org and NVD. The CVE record and NVD detail pages provide comprehensive information about the vulnerability, including its description, CVSS score, and affected versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54819 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54819
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54819 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54819
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.