VYPR
Critical severity9.9NVD Advisory· Published Apr 23, 2026· Updated Apr 23, 2026

CVE-2026-39440

CVE-2026-39440

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Patches

Vulnerability mechanics

References

1

News mentions

1
CVE-2026-39440 · Critical · VYPR