CVE-2026-105889: Tickera

Critical severity, CVSS 9.3.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.

Affected products

  • Tickera Tickera: up to and including 3.6.0.6

Published 2026-10-10. Last modified 2026-10-10.