CVE-2024-29401: Mindskip Xzs-MySQL

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.

Affected products

Published 2024-03-26. Last modified 2026-06-17.