PT-2026-78367 · Zoo · Zoo

CVE-2026-74804

·

Published

2026-08-19

·

Updated

2026-08-20

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zoo versions prior to 4.1.64
Description An unauthenticated SQL injection exists in the element() function of the ItemController. The issue occurs because the filter type request value and the type filter array are interpolated into the database query without proper quoting or escaping.
Recommendations Update Zoo to version 4.1.64 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74804

Affected Products

Zoo