CVE-2026-31858 | Craft CMS up to 5.9.8 actionSearch sql injection (GHSA-g7j6-fmwx-7vp8)
A vulnerability was found in Craft CMS up to 5.9.8. It has been declared as critical. This vulnerability affects the function ElementSearchController::actionSearch. The manipulation results in sql injection.
This vulnerability is identified as CVE-2026-31858. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.