{"apiVersion":"1.0","identifier":"CVE-2026-68000","description":"The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through FreeMarker ${size} without being parameterized and bound. The built-in SqlInjectionUtil employs regular expression blacklist filtering, yet keywords like CREATE/TABLE/SET/PREPARE/EXECUTE are not included in the list, allowing for bypassing. Attackers can execute stacked SQL statements without logging in.","publishedAt":"2026-08-26T20:17:57","lastModifiedAt":"2026-08-26T20:17:57","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-68000","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00152,"riskScore":0,"affectedProduct":"MCMS","affectedVersions":"<=6.2.0","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-68000","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-68000","en":"https://www.redsauce.net/en/cves/CVE-2026-68000","fr":"https://www.redsauce.net/fr/cves/CVE-2026-68000","pt":"https://www.redsauce.net/pt/cves/CVE-2026-68000","de":"https://www.redsauce.net/de/cves/CVE-2026-68000","sk":"https://www.redsauce.net/sk/cves/CVE-2026-68000","el":"https://www.redsauce.net/el/cves/CVE-2026-68000"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-68000"}}