SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary data from the database, reset administrator account passwords, and gain unauthorized access to the Packages Manager in the Admin Panel, potentially enabling remote code execution.
References
| Link | Resource |
|---|---|
| https://karmainsecurity.com/KIS-2026-08 | Exploit Third Party Advisory |
| https://socialengine.com | Product |
| https://www.vulncheck.com/advisories/socialengine-sql-injection-via-activity-index-get-memberall | Third Party Advisory |
| http://seclists.org/fulldisclosure/2026/Apr/12 | |
| https://karmainsecurity.com/KIS-2026-08 | Exploit Third Party Advisory |
| https://karmainsecurity.com/pocs/CVE-2026-41460.php | Exploit |
Configurations
History
29 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
27 Apr 2026, 14:54
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:socialengine:socialengine:*:*:*:*:*:*:*:* | |
| First Time |
Socialengine
Socialengine socialengine |
|
| References | () https://karmainsecurity.com/KIS-2026-08 - Exploit, Third Party Advisory | |
| References | () https://socialengine.com - Product | |
| References | () https://www.vulncheck.com/advisories/socialengine-sql-injection-via-activity-index-get-memberall - Third Party Advisory | |
| References | () https://karmainsecurity.com/pocs/CVE-2026-41460.php - Exploit |
23 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-23 15:37
Updated : 2026-04-29 20:16
NVD link : CVE-2026-41460
Mitre link : CVE-2026-41460
CVE.ORG link : CVE-2026-41460
JSON object : View
Products Affected
socialengine
- socialengine
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
