SQL Injection Affecting sulu/sulu package, versions <2.6.25>=3.0.0, <3.0.8


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.33% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about SQL Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-SULUSULU-20186947
  • published28 Sept 2026
  • disclosed23 Sept 2026
  • creditUnknown

Introduced: 23 Sep 2026

NewCVE-2026-92692  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade sulu/sulu to version 2.6.25, 3.0.8 or higher.

Overview

sulu/sulu is a highly extensible open-source PHP content management system based on the Symfony framework.

Affected versions of this package are vulnerable to SQL Injection via the categories query parameter in the Smart Content category filter. An attacker can infer the existence of, and disclose, content nodes they should not access, or cause resource-intensive queries and errors, by injecting crafted input into the parameter. This is only exploitable if a public page renders a Smart Content element with category filtering enabled.

Workaround

This vulnerability can be mitigated by manually casting each ID to an integer where it is concatenated into the category (and, defensively, tag and audience-targeting) WHERE clause in the content Smart Content query builder, or by disabling category filtering on publicly reachable Smart Content elements until the patch is applied.

CVSS Base Scores

version 4.0
version 3.1