CVE-2026-15804: Metaguru Hcm

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the confidentiality, integrity, and availability of database data.

Affected products

  • Metaguru Hcm: from 7, before 7.5.3 (fixed in 7.5.3); from 8, before 8.1.7.1 (fixed in 8.1.7.1)

Published 2026-07-15. Last modified 2026-07-15.