Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.