Report: - LayerBB 1.1.4 SQL Injection via search_query Parameter CVE-2021-47954

Report: - LayerBB 1.1.4 SQL Injection via search_query Parameter CVE-2021-47954

CVE ID :CVE-2021-47954 Published : May 16, 2026, 3:26 p.m. | 32 minutes ago Description :LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the search_query parameter. Attackers can send POST requests to /search.php with malicious search_query values using CASE WHEN statements to extract sensitive database information. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
May 16, 2026
Affected Product: php
Impact: SQL injection