CVE-2026-92692: Sulu
Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Sulu/Component/Content/SmartContent/QueryBuilder.php that concatenates category identifiers from the public categories query parameter into a JCR-SQL2 WHERE clause without numeric validation. On a public page containing a category-filtered Smart Content block, an unauthenticated attacker can alter query conditions to infer or enumerate content-repository nodes, including unpublished content, or submit malformed and expensive query fragments that degrade availability; this path does not modify repository data. This issue is fixed in versions 2.6.25 and 3.0.8.
Affected products
- Sulu Sulu: before 2.6.25 (fixed in 2.6.25); from 3.0.0, before 3.0.8 (fixed in 3.0.8)
Published 2026-09-23. Last modified 2026-09-23.