S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 9, 2026

CVE-2026-8054 Scanner

CVE-2026-8054 Scanner - SQL Injection (SQLi) vulnerability in dotCMS Core

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-8054
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11.04-1 through 26.04.28-02 allows remote unauthenticated attackers to read, modify, or destroy arbitrary database content. The endpoints did not enforce authentication and accepted unsanitized input used in dynamically constructed SQL. The fix in dotCMS Core 26.04.28-03 requires an authenticated backend user with the publishing-queue portlet permission. LTS releases are not affected as the vulnerable code path was never backported.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
dotCMS Coreby dotCMS
25.11.04-1
Updated Aug 22, 2026View on NVD →
Detail

The dotCMS Core is an open-source content management system used by various enterprises to manage digital content effectively. Developed by dotCMS, it serves to streamline content creation and delivery with its robust platform. The software is versatile, designed to be used across multiple digital channels, enhancing the customer experience. Its purpose includes facilitating easy integration for developers and providing marketers with intuitive tools. This CMS is valued for its ability to support a wide array of digital marketing strategies, providing the flexibility and functionality needed for content-rich websites.

SQL Injection (SQLi) is a type of injection attack that makes it possible to execute malicious SQL statements. DotCMS Core is vulnerable to SQL Injection due to unsanitized input in its Publish Audit API endpoints. This vulnerability could allow a remote unauthenticated attacker to interact with the back-end database arbitrarily. SQL Injection can result in unauthorized viewing of user data, or it may target the system for modification of data or execution of administrative operations on the database. Preventing SQL Injection vulnerabilities involves using parameterized queries to ensure correct and safe query execution.

The SQL Injection vulnerability in dotCMS Core is found within the Publish Audit API, specifically at the endpoints /api/auditPublishing/get and /api/auditPublishing/getAll. The vulnerability arises from a lack of input sanitization, which allows attackers to inject arbitrary SQL commands. This injection occurs by manipulating input strings to alter database query execution. Exploitation requires crafting specific payloads that induce the database to perform unauthorized operations. By exploiting this, attackers can trigger unauthorized sleeps or injections that disrupt normal database behavior.

If exploited, this vulnerability can have significant consequences, such as enabling attackers to read, modify, or even delete database contents. The entire database may be compromised, leading to unauthorized access to sensitive data. Additionally, attackers could corrupt database integrity, affecting application reliability. In a severe case, this could result in extensive data loss or application downtime. Organizations may face repercussions such as financial loss, reputational damage, or legal liabilities if customer data is exposed.

REFERENCES

Solution Advice
  • Upgrade to dotCMS Core version 26.04.28-03 or later to address the SQL Injection vulnerability.
  • Review your API endpoints to ensure input sanitization and validation.
  • Implement parameterized queries to prevent SQL Injection.
  • Conduct regular security audits and testing to identify potential vulnerabilities early.
  • Educate developers on secure coding practices and SQL Injection risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.