Critical severity9.3NVD Advisory· Published Mar 25, 2026· Updated Apr 24, 2026
CVE-2026-25371
CVE-2026-25371
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allows Blind SQL Injection.This issue affects Lumise Product Designer: from n/a through < 2.0.9.
Affected products
1- Range: < 2.0.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.