HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-48448 — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia...

·Source: NIST NVD

Updated:

Executive Summary

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed.

Analysis

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed. CVSS Score: 8.6. Published: 2026-07-30T03:16:24.810.

Indicators of Compromise (1)

CVE (1)
CVE-2026-48448
Source Attribution

Originally published by NIST NVD on Jul 30, 2026. Verified by: NIST.

Related Threats

HIGHVulnerability

NVD HIGH: CVE-2026-16635 — The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in a...

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain whic

CVE-2026-16635
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-16144 — The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vu...

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This

CVE-2026-16144
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-15964 — The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication ...

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication — accepting an attacker-supplied `email` parameter with the `setnewpassword` operation an

CVE-2026-15964
NIST NVD