All verified exploits

CVE-2026-28562 ORDER BY SQL Injection

Deterministic critical wpForo Added cve-verified-cve-2026-28562

Injects a closing parenthesis into the wpfob ORDER BY parameter on the recent topics page, triggering a MySQL syntax error that confirms unquoted SQL injection. No authentication required.

Is your app exploitable through CVE-2026-28562?

Scan your domain free