A SQL injection vulnerability has been identified in the light0011 CMS at specific commit hashes (c774dce31c6df0055568a8d5c53d964d99be199d and f72cf46f601efb2a0618c3814cc2f61380b38930). The flaw resides in the ChapterModel::searchChapter function within App/Home/Controller/ChapterController.class.php, specifically in the Query Builder component. Attackers can manipulate the 'content' argument to perform SQL injection attacks remotely. A public exploit has already been released, increasing the risk of active exploitation. The product does not use versioning, making it impossible to identify specific affected or unaffected releases. The project maintainer was notified via a GitHub issue report but has not yet responded. This vulnerability poses a significant risk to any deployment of this CMS.