CVE-2024-28395: Best-Kit Bestkit Popup

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.

Affected products

  • Best-Kit Bestkit Popup: up to and including 1.7.2

Published 2024-03-20. Last modified 2026-06-17.