Review reviewCritical
CVE-2026-49067
yydevelopment Advanced 301 and 302 Redirect
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
- CVSS
- 9.3
- EPSS
- 0.29% 21.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.16
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
The CVSS severity warrants an early asset and exposure review.
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
Confirm exposure before applying a vendor-supported change.
Confirm that yydevelopment Advanced 301 and 302 Redirect and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.