CVE-2024-57151: Rockoa Xinhu

Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.

SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function

Affected products

  • Rockoa Xinhu: up to and including 2.6.5

Published 2025-03-18. Last modified 2026-06-17.