CVE-2019-11880: Commsy

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

CommSy through 8.6.5 has SQL Injection via the cid parameter. This is fixed in 9.2.

Affected products

  • Commsy Commsy: up to and including 8.6.5

Published 2019-05-22. Last modified 2026-06-17.