CVE-2021-47872 HIGH

CVE-2021-47872: SEO Panel < 4.9.0 - 'order_col' Blind SQL Injection

Vendor Seo Panel
Product SEO Panel
Weakness CWE-89 · SQLi
Published January 21, 2026
Last update April 7, 2026

CVSS base score

7.0/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL code into the order column parameter.

Key dates

02Disclosure timeline

January 21, 2026 CVE published
April 7, 2026 Record updated