CVE-2020-26677: Vfairs

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.

Affected products

  • Vfairs Vfairs: version 3.3 only

Published 2021-05-26. Last modified 2026-07-09.