CVE-2026-39440

· NIST NVD ↗

Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1.

CRITICAL
CVSS severity
9.9
CVSS base score
2026-04-23
Published

CWE codes

CWE-94

Sources