Junglewise Threat Intelligence

CVE-2026-23959: CoreShop Vulnerable to SQL Injection via Admin customer-company-modifier

CVE-2026-23959 · Severity: medium · CVSS 4 · Published 2026-01-21

Technologies: coreshop/core-shop (Packagist). Vendors: Packagist.

Executive brief

CoreShop Vulnerable to SQL Injection via Admin customer-company-modifier

Affected products

  • Packagist coreshop/core-shop

Related threats