CVE-2024-28294: Limbas

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter.

Affected products

  • Limbas Limbas: up to and including 5.2.14

Published 2024-04-29. Last modified 2026-06-17.