CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108107

CRITICALCVSS 9.8NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-108107 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108107

CRITICALCVSS 9.8NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]