CVE-2021-47872

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
21/01/2026
Last modified:
21/01/2026

Description

SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL code into the order column parameter.