CVE-2017-7410: Websitebaker

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) display_name parameter.

Affected products

Published 2017-04-03. Last modified 2026-06-17.