High severity7.5NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-79323
CVE-2026-79323
Description
Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and admin identifiers via a POST request to /graphql.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.2.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.