CVE-2026-73698:FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute
FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate ra