CVE-2026-4815: Schiocco Support Board

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve, create, update and delete database via 'calls[0][message_ids][]' parameter in '/supportboard/include/ajax.php' endpoint.

Affected products

  • Schiocco Support Board: before 3.7.8 (fixed in 3.7.8)

Published 2026-03-25. Last modified 2026-06-17.