CVE-2026-30711

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session.inc.php file via the referer and user-agent.

Published 2026-03-19. Last modified 2026-06-17.