CVE-2026-40529: Kanata Limited CMS Alaya
Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.
CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface.
Affected products
- Kanata Limited CMS Alaya: up to and including 7.4.1.4
Published 2026-04-23. Last modified 2026-06-17.