# CVE-2026-9422

## Summary

- **CVE ID:** CVE-2026-9422
- **Severity:** MEDIUM
- **CVSS Score:** 7.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-74, CWE-707
- **Published:** May 25, 2026
- **Last Modified:** May 29, 2026

## Description

A vulnerability was identified in KLiK SocialMediaWebsite 1.0. This issue affects some unknown processing of the component HTTP POST Request Parameter Handler. Such manipulation leads to injection. The attack can be launched remotely. The exploit is publicly available and might be used.

## Affected Products

- n/a — KLiK SocialMediaWebsite (1.0)

## References

- [CNA](https://vuldb.com/vuln/365403)
- [CNA](https://vuldb.com/vuln/365403/cti)
- [CNA](https://vuldb.com/submit/813734)
- [CNA](https://vuldb.com/submit/813736)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.30%
- **EPSS Percentile:** 22.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._