CVE-2026-61518P2HIGHCVSS 8.8≥ 3.2.0, ≤ *·≥ 3.3.0, ≤ *2026-08-19
CVE-2026-61518 [HIGH] CWE-89 CVE-2026-61518: ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id pa
ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. The built-in SQL injection scanner does not block quote-free boolean payloads and does not reject requ
nvd