CVE-2026-39948 - Cacti has SQL Injection via rfilter parameter in RLIKE clauses
CVE ID :CVE-2026-39948 Published : June 24, 2026, 11:06 p.m. | 4 hours, 4 minutes ago Description :Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the raw accessor grv() (rather than gfrv() with...