Product
Plesk Obsidian versions prior to 18.0.80.1 and 18.0.79.5 are vulnerable to a blind SQL injection (CVE-2026-64636) which allows unauthenticated or low-privileged attackers to execute unauthorized database queries.