CVE-2018-5211: Phpsugar PHP Melody

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.

Affected products

Published 2018-01-09. Last modified 2026-06-17.