CVE-2026-37505: v2board

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort parameter from user input is passed directly to User::orderBy($sort, $sortType) without validation. An authenticated admin can sort users by any database column including password, remember_token, and other sensitive fields, enabling information disclosure through ordering analysis.

Affected products

  • v2board v2board: up to and including 1.7.4

Published 2026-05-01. Last modified 2026-06-17.