VYPR
Unrated severityNVD Advisory· Published Jan 13, 2026· Updated Apr 7, 2026

Aero CMS 0.0.1 - SQL Injection

CVE-2022-50895

Description

Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system.

Affected products

2
  • Statamic/CMSllm-fuzzy
    Range: =0.0.1
  • MegaTKC/Aero CMSv5
    Range: 0.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.