CVE-2026-6562 is a SQL injection vulnerability in dameng100 muucmf version 1.9.5.20260309, a PHP-based content management framework. An unauthenticated remote attacker can inject malicious SQL commands through the search function, potentially accessing or modifying the underlying database. No vendor patch exists; the vendor did not respond to disclosure, and a public exploit is available.