4.7
/ 10
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Description
CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface.
Basic Information
ID
CVE-2026-40529
Source
jpcert
Published
Apr 23, 2026 at 04:15
Affected Product
Vendor
KANATA Limited
Product
CMS ALAYA
Version
7.4.1.4 and earlier
Affected Versions
KANATA Limited CMS ALAYA 7.4.1.4 and earlier