By weakness (CWE)
CWE-74: related vulnerabilities
CVEs classified under CWE-74. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
264 published vulnerabilities · page 3 of 3
- CVE-2026-13530MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0. An authenticated attacker can manipulate the 'editid' parameter in the /appointmentdetail.php file to inject malicious SQL commands. This vulnerability allows remote exploitation and could enable an attacker to read, modify, or delete sensitive appointment and patient data. Public exploits are available, increasing the risk of active exploitation.
- CVE-2026-13531MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 within the /department.php file. An authenticated attacker can manipulate the editid parameter to execute arbitrary SQL commands, potentially allowing unauthorized access to, modification of, or deletion of database records. Public exploit code is available, elevating the practical risk.
- CVE-2026-13532MEDIUM 6.3
itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in the departmentDoctor.php file that allows authenticated users to execute arbitrary SQL queries by manipulating the deptid parameter. An attacker with valid login credentials can remotely exploit this flaw to read, modify, or delete database records. Public exploit code is available, increasing the risk of active exploitation.
- CVE-2026-13535MEDIUM 6.3
CodeAstro Human Resource Management System version 1.0 contains a SQL injection vulnerability in its employee management interface. An authenticated user can manipulate the ID parameter in the file viewing function to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive HR data. The vulnerability requires valid login credentials but can be exploited remotely without special tools or user interaction.
- CVE-2026-13538MEDIUM 6.3
A command injection vulnerability exists in Wavlink WL-NU516U1-A M16U1_V240425 routers. An authenticated attacker can send specially crafted POST requests to the wireless configuration endpoint (/cgi-bin/wireless.cgi) with malicious input in SSID or authentication-related parameters. This allows execution of arbitrary system commands with the privileges of the web server process. The vulnerability requires valid credentials to exploit, but the attack surface is wide since SSID and password parameters are commonly modified during normal router administration.
- CVE-2026-13541MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0, specifically in the doctor password change functionality. An authenticated user can manipulate the newpassword parameter in /doctorchangepassword.php to inject malicious SQL commands. This allows an attacker to read, modify, or delete database contents without requiring elevated privileges. The vulnerability is remotely exploitable and public exploit code has already been released, increasing the risk of active exploitation.
- CVE-2026-13542MEDIUM 6.3
itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in its doctor profile functionality. An authenticated attacker can manipulate the doctorname parameter in /doctorprofile.php to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive healthcare data. The vulnerability requires valid login credentials but can be exploited without user interaction once authenticated. Public disclosure means defensive preparation should be treated as urgent.
- CVE-2026-13548MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate database queries through the editid parameter in the /doctortimings.php file. An attacker with valid login credentials can exploit this flaw to read, modify, or delete sensitive hospital data. The vulnerability is not yet tracked by CISA's Known Exploited Vulnerabilities catalog, but public exploit code is available, increasing the practical risk of opportunistic attacks.
- CVE-2026-13572MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to execute arbitrary SQL commands by manipulating the patientid parameter in the /insertbillingrecord.php file. An attacker with valid login credentials can exploit this remotely to read, modify, or delete database records. Public disclosure means defensive measures should be prioritized immediately.
- CVE-2026-13578MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate the editid parameter in the patientdetail.php file, potentially compromising patient data confidentiality and integrity. The vulnerability requires valid login credentials but can be exploited remotely over the network. Public exploit code is already available, increasing the practical risk to deployed instances.
- CVE-2026-13579MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0. An authenticated attacker can manipulate the password change function to execute arbitrary SQL queries. This allows an attacker with valid login credentials to read, modify, or delete patient data stored in the hospital's database. The vulnerability is in the /patientchangepassword.php file and requires no user interaction beyond the attacker sending a crafted request.
- CVE-2026-14619MEDIUM 6.3
A SQL injection vulnerability has been discovered in itsourcecode Hospital Management System version 1.0. An authenticated attacker can manipulate the 'editid' parameter in the /medicine.php file to inject malicious SQL commands. This allows an attacker who has valid login credentials to read, modify, or delete data in the underlying database. Public exploit code is available, increasing the risk of active exploitation.
- CVE-2026-14638MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the patient.php file. An authenticated attacker can manipulate the 'editid' parameter to execute arbitrary SQL queries, potentially reading, modifying, or deleting patient data. The vulnerability requires valid login credentials but no additional user interaction, making it exploitable by insiders or through credential compromise. Public exploit code has been released.
- CVE-2026-14639MEDIUM 6.3
CodeAstro Ecommerce Website version 1.0 contains a SQL injection vulnerability in its customer account management functionality. An authenticated attacker can manipulate the 'c_name' parameter in the my_account.php?edit_account endpoint to inject malicious SQL commands, potentially compromising data confidentiality, integrity, and availability. Because the vulnerability requires prior authentication and has been publicly disclosed, it presents a moderate but actionable risk that organizations using this software should address promptly.
- CVE-2026-14657MEDIUM 6.3
A SQL injection vulnerability has been discovered in code-projects Assessment Management version 1.0. An authenticated attacker can inject malicious SQL code through the squestions[] parameter in the marking-scheme.php file, allowing them to read, modify, or delete database records. The vulnerability requires valid login credentials but does not require user interaction, making it a concern for organizations deploying this assessment platform.
- CVE-2026-14658MEDIUM 6.3
A SQL injection vulnerability exists in code-projects Assessment Management version 1.0 that allows authenticated users to manipulate the smarksrange[] parameter in the marking-scheme.php file to execute arbitrary SQL commands. An attacker with valid login credentials can exploit this remotely to read, modify, or delete database records without additional privileges. The vulnerability is already public and proof-of-concept code is available, raising the practical risk despite the medium CVSS score.
- CVE-2026-14659MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the patient appointment functionality. An authenticated attacker can inject malicious SQL commands through the 'patiente' parameter in the /patientappointment.php file to read, modify, or delete database records. The vulnerability requires a valid user login but can be exploited remotely, and proof-of-concept details are publicly available.
- CVE-2026-14689MEDIUM 6.3
CodeAstro Apartment Visitor Management System version 1.0 contains a SQL injection vulnerability in its apartment addition function. An authenticated attacker can manipulate the apartment number parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. Proof-of-concept code is publicly available, increasing the likelihood of active exploitation.
- CVE-2026-14691MEDIUM 6.3
SourceCodester Multi-Vendor Online Grocery Management System version 1.0 contains a code injection flaw in its settings update functionality. An authenticated attacker can manipulate the content parameter to inject malicious code, which the application will execute. The vulnerability requires login credentials but poses moderate risk due to the simplicity of exploitation and confirmed public disclosure.
- CVE-2026-14692MEDIUM 6.3
A SQL injection vulnerability exists in SourceCodester Multi-Vendor Online Grocery Management System versions 1.0 and 5.7.26. An authenticated attacker can inject malicious SQL commands through the POST parameters of the shop type save function, potentially reading, modifying, or deleting database contents. The vulnerability requires valid login credentials but no special privileges, and can be exploited over the network. Public exploit code is available.
- CVE-2026-14694MEDIUM 6.3
A SQL injection vulnerability exists in SourceCodester's Multi-Vendor Online Grocery Management System version 1.0. An authenticated attacker can manipulate the ID parameter in the order cancellation function to inject malicious SQL commands. This allows an attacker with valid login credentials to read, modify, or delete database contents. The vulnerability was disclosed publicly, making attack techniques potentially available to a wider audience.
- CVE-2026-14701MEDIUM 6.3
A SQL injection vulnerability exists in the Internship Management System version 1.0, specifically in the password change function. An authenticated user can manipulate the 'Current' parameter to inject malicious SQL commands, potentially accessing or modifying sensitive data in the database. The vulnerability requires login credentials but is otherwise straightforward to exploit, and proof-of-concept code is already publicly available.
- CVE-2026-14703MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate the editid parameter in the /patientorder.php file to execute arbitrary SQL queries. The vulnerability requires valid login credentials to exploit but does not require user interaction once authenticated. Public disclosure of this vulnerability means exploitation techniques are already available to potential attackers.
- CVE-2026-14706MEDIUM 6.3
A SQL injection vulnerability exists in code-projects Online Examination 1.0 affecting the quiz creation feature. An authenticated attacker can manipulate multiple input fields (name, total, right, wrong, time, tag, desc) in the /update.php?q=addquiz endpoint to inject malicious SQL commands. This allows unauthorized data access, modification, or deletion within the application's database. The vulnerability requires valid login credentials but can be exploited remotely with no user interaction.
- CVE-2026-14717MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the patient login function. An authenticated attacker can manipulate the loginid parameter in /patientlogin.php to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive patient data. The vulnerability requires valid credentials but is easy to exploit and poses a direct risk to healthcare information confidentiality and integrity.
- CVE-2026-14730MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0, specifically in the /patientprofile.php file. An authenticated attacker can manipulate the patientname parameter to execute arbitrary SQL commands against the underlying database. This allows an attacker who has legitimate system access to read, modify, or delete patient records and potentially other sensitive data. Public exploit code is available, increasing the practical risk.
- CVE-2026-14731MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 within the /patientreport.php file. An authenticated attacker can manipulate the 'editid' parameter to inject malicious SQL commands, potentially allowing them to read, modify, or delete patient data. Public exploit code is available, increasing the practical risk of exploitation. The vulnerability requires valid login credentials but operates over the network without additional user interaction.
- CVE-2026-14751MEDIUM 6.3
A SQL injection vulnerability has been discovered in mjperpinosa stumasy, a rolling-release software project. An attacker with valid login credentials can inject malicious SQL commands through the search functionality by manipulating the field_name parameter. This allows unauthorized reading and modification of database records, or potentially disrupting database availability. Because the project uses continuous delivery and has not yet responded to disclosure, affected versions are not precisely documented.
- CVE-2026-14766MEDIUM 6.3
CodeAstro Apartment Visitor Management System version 1.0 contains a SQL injection vulnerability in its search functionality. An authenticated attacker can exploit a flaw in the /apartment-visitor/search-result.php endpoint by manipulating the searchdata POST parameter to inject arbitrary SQL commands. This allows an attacker with valid login credentials to read, modify, or delete database records without authorization. Public exploit code exists for this vulnerability, increasing the practical risk.
- CVE-2026-14767MEDIUM 6.3
CodeAstro Ecommerce Website version 1.0 contains a SQL injection vulnerability in its customer confirmation page. An authenticated attacker can manipulate the invoice_no parameter to inject malicious SQL commands, potentially compromising database integrity and confidentiality. The vulnerability requires valid user credentials but no special interaction, and exploit code has already been released publicly.
- CVE-2026-14773MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to inject malicious SQL commands through the patientid parameter in the /payment.php file. An attacker with valid login credentials can exploit this flaw to read, modify, or delete sensitive healthcare data. Public exploit code is available, increasing the risk of active exploitation.
- CVE-2026-14774MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the payment discharge workflow. An authenticated attacker can manipulate the patientid parameter in /paymentdischarge.php to execute unauthorized database queries, potentially reading, modifying, or deleting patient and financial records. The vulnerability requires valid login credentials but presents direct risk to patient data confidentiality and billing system integrity.
- CVE-2026-14795MEDIUM 6.3
A SQL injection vulnerability exists in CodeAstro Apartment Visitor Management System version 1.0. An authenticated attacker can manipulate the 'remark' parameter in the /apartment-visitor/action-visitor.php file to inject malicious SQL commands. This allows unauthorized access to, modification of, or deletion of database records. The vulnerability requires valid login credentials to exploit, and proof-of-concept code has been publicly disclosed.
- CVE-2026-14796MEDIUM 6.3
CodeAstro's Apartment Visitor Management System version 1.0 contains a SQL injection vulnerability in its report generation feature. An authenticated attacker can manipulate the 'fromdate' parameter in the /apartment-visitor/report.php file to inject malicious SQL commands, potentially compromising the confidentiality, integrity, and availability of the application database. The exploit code is publicly available, increasing the practical risk to organizations using this software.
- CVE-2026-14797MEDIUM 6.3
A SQL injection vulnerability exists in CodeAstro Apartment Visitor Management System version 1.0. An authenticated user can manipulate the 'editid' parameter in the /apartment-visitor/edit-apartment.php file to inject malicious SQL commands. The vulnerability allows remote exploitation and has been publicly disclosed, increasing the risk of active exploitation.
- CVE-2026-14798MEDIUM 6.3
CVE-2026-14798 is a SQL injection vulnerability in CodeAstro Apartment Visitor Management System version 1.0. An authenticated attacker can inject malicious SQL code through the 'visname' parameter in the visitor entry form, potentially compromising the confidentiality, integrity, and availability of the underlying database. Public exploit code exists, elevating the practical risk despite the MEDIUM CVSS score.
- CVE-2026-14799MEDIUM 6.3
CodeAstro Ecommerce Website version 1.0 contains a SQL injection vulnerability in its customer account management functionality. An authenticated attacker can manipulate the delete_wishlist parameter in the /customer/my_account.php?my_wishlist endpoint to execute arbitrary SQL commands against the application's database. The flaw requires valid login credentials but no elevated privileges, and can be exploited over the network. Public exploit code exists, increasing the risk of active attacks.
- CVE-2026-20220MEDIUM 6.3
Cisco Crosswork Network Controller's web management interface contains a flaw in how it validates input to its configuration template engine. An authenticated user with template write permissions can send specially crafted requests to execute arbitrary commands on the underlying operating system, but only within directories where the template user account has write access. This is a post-authentication attack requiring valid credentials and specific permission levels.
- CVE-2026-10222MEDIUM 5.6
A vulnerability exists in NousResearch's hermes-agent software that allows attackers to inject malicious code through improper sanitization of environment variables. The flaw resides in the configuration parsing logic and can be exploited remotely, though successful exploitation requires substantial technical knowledge and effort. While a public exploit exists, the attack surface is limited by high complexity requirements. This is a medium-severity issue affecting versions up to 2026.4.30.
- CVE-2026-13529MEDIUM 5.6
YzmCMS versions up to 7.5 contain a SQL injection vulnerability in the installation script that can be triggered by manipulating the siteurl parameter. While the flaw allows an attacker to read, modify, or delete database contents, exploiting it requires navigating non-trivial technical barriers and is not straightforward to execute. The vendor has not responded to early disclosure attempts, leaving users without an official patch timeline.
- CVE-2026-10688MEDIUM 5.5
A code injection vulnerability exists in ahujasid blender-mcp, a tool used for integrating Blender with model context protocol systems. An authenticated attacker can inject and execute arbitrary code by manipulating the 'code' parameter passed to the execute_blender_code function in the server. The vulnerability has been publicly disclosed and exploit code is available. The project uses rolling releases, making it difficult to identify fixed versions; however, the maintainers have been notified but have not yet responded with a patch or mitigation guidance.
- CVE-2026-12223MEDIUM 5.5
Yealink SIP-T46U IP phones running firmware version 108.86.0.118 contain a command injection vulnerability in their web service that allows authenticated users on the local network to execute arbitrary commands by manipulating network parameters. An attacker with local network access and valid credentials can exploit this flaw to compromise the phone's integrity and confidentiality. A patched firmware version (108.87.0.23) is available, though the vendor notes the fix currently exists only in a technical support branch and has not been publicly released yet.
- CVE-2026-54231MEDIUM 5.5
A local user can inject arbitrary content into system log files processed by the Automatic Bug Reporting Tool (ABRT) in libreport. When a program crashes, ABRT collects diagnostic information from the system journal. However, the scripts that gather this information don't properly filter out special characters that control log formatting. An attacker with local access can embed newline characters in their own log messages, which ABRT then reads and writes to its crash dump directory files without cleaning them up. This allows the attacker to manipulate files that root processes create, potentially altering important diagnostic records or injecting misleading content into crash reports.
- CVE-2026-46546MEDIUM 5.4
Frappe Learning Management System prior to version 2.53.0 contains a vulnerability where authenticated users can inject malicious code into certain editable fields. When these fields are displayed in page metadata, visiting users' browsers are automatically redirected to attacker-controlled URLs without their knowledge. The vulnerability requires an attacker to have valid user credentials and for a victim to visit a page containing the injected content, but once triggered, it can lead to credential theft, malware distribution, or other social engineering attacks.
- CVE-2026-11487MEDIUM 5.3
Neovim versions up to 0.12.2 contain a command injection vulnerability in the secure.lua module's path-handling function. An authenticated local attacker can manipulate the path argument to execute arbitrary commands with the privileges of the Neovim process. The vulnerability requires local access and user-level privileges, making it a risk primarily in multi-user systems or environments where untrusted users have shell access to machines running Neovim.
- CVE-2026-12822MEDIUM 5.3
A code injection vulnerability exists in Langflow (an AI/LLM orchestration framework) up to version 1.9.3, affecting the Bundle URL Loader component. An authenticated local user can manipulate input to the loader to inject and execute arbitrary code on the affected system. The vulnerability requires local access and valid user credentials, limiting its reach to internal threats or compromised accounts. Langflow's maintainers were notified but did not provide a response or patch timeline.
- CVE-2026-13501MEDIUM 5.3
ANTLR4, a widely-used parser generator framework, contains a command injection vulnerability in its Go code generation component. The vulnerability exists in how the GoTarget module processes input when invoking the Go formatter (gofmt). An attacker with local system access can craft malicious input that breaks out of the intended command context, allowing arbitrary command execution with the privileges of the user running ANTLR4. This affects ANTLR4 versions up to and including 4.13.2.
- CVE-2026-15035MEDIUM 5.3
A command injection vulnerability exists in bentoml OpenLLM 0.6.30 where attackers with local access can manipulate the `cmd` argument passed to the `async_run_command` function, allowing them to execute arbitrary system commands. The vulnerability requires local system access and valid credentials, limiting its immediate threat scope but posing risk to multi-tenant or shared development environments. Public exploit information is available.
- CVE-2026-49098MEDIUM 5.3
Apache Camel's Kafka component contains a header-injection vulnerability that allows untrusted HTTP clients to redirect Kafka messages to unintended topics. When an HTTP consumer (like platform-http) is chained into a Kafka producer within the same Camel route, attackers can inject kafka.* headers through HTTP requests to override the configured target topic, alter timestamps, or target specific partitions. This is possible because the HTTP header filter only blocks Camel-prefixed headers, allowing kafka.* headers to pass through and reach the Kafka producer unfiltered. No authentication is required if the HTTP endpoint is publicly accessible.
- CVE-2026-49099MEDIUM 5.3
Apache Camel's Salesforce component has a vulnerability that allows attackers to hijack database queries and operations by injecting malicious headers through HTTP requests. When a route connects an HTTP endpoint to Salesforce, an unauthenticated attacker can override the intended SOQL queries, target objects, or API calls by setting specific HTTP headers. These operations execute with full permissions of the Salesforce integration user, potentially exposing sensitive data or performing unauthorized modifications. The issue stems from Camel's HTTP header filtering not recognizing Salesforce control headers as privileged, allowing them to pass through from untrusted external sources.
- CVE-2026-11455MEDIUM 5.0
MetaGPT versions up to 0.8.2 contain a command injection vulnerability in the common utility module. An authenticated attacker can manipulate the mermaid.path argument to inject arbitrary system commands, potentially leading to unauthorized code execution. The flaw requires significant technical knowledge to exploit and has become public, increasing risk posture for organizations running affected versions.
- CVE-2026-10155MEDIUM 4.7
A SQL injection vulnerability exists in Bdtask Multi-Store Inventory Management System version 1.0 within the Accounts Report Handler. An authenticated attacker can manipulate the 'dtpToDate' parameter in the accounts report search function to inject malicious SQL commands. While the vulnerability requires high privileges to exploit, successful attacks could leak sensitive financial data, modify account records, or disrupt reporting functionality. Public exploit code is available, increasing real-world risk.
- CVE-2026-10171MEDIUM 4.7
A SQL injection vulnerability exists in code-projects Online Music Site version 1.0 that allows authenticated administrators to manipulate the ID parameter in the album update functionality. An attacker with admin credentials can inject malicious SQL commands through the /Administrator/PHP/AdminUpdateAlbum.php endpoint, potentially compromising database integrity and confidentiality. The vulnerability has been publicly disclosed and exploit code is available, increasing the likelihood of active exploitation.
- CVE-2026-10237MEDIUM 4.7
A SQL injection vulnerability was identified in SourceCodester Water Billing Management System version 1.0. An authenticated administrator can manipulate the ID parameter in the user management interface to inject malicious SQL commands, potentially reading or modifying sensitive database records. The vulnerability requires administrative privileges to exploit but poses a risk to data integrity and confidentiality within billing systems. Public proof-of-concept code exists, elevating the practical risk of exploitation.
- CVE-2026-10248MEDIUM 4.7
SourceCodester's Pharmacy Sales and Inventory System version 1.0 and earlier contains a CSV injection vulnerability in its supplier creation interface. An authenticated attacker with high privileges can inject malicious CSV formulas through the Address or Company Name fields when exporting supplier data, potentially causing data corruption, formula execution, or information disclosure when a user opens the exported file in a spreadsheet application.
- CVE-2026-11448MEDIUM 4.7
GL.iNet GL-MT3000 routers running firmware version 4.4.5 and earlier contain a command injection flaw in the Minidlna service. An authenticated remote attacker can manipulate a specific parameter to inject arbitrary commands, potentially allowing them to execute code on the device. The vulnerability requires administrative privileges to exploit and has been resolved in firmware version 4.7 through enhanced input validation added to the SDK.
- CVE-2026-12175MEDIUM 4.7
CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in its student creation interface. An authenticated administrator can exploit this flaw by manipulating the admission number field to inject malicious SQL commands, potentially reading, modifying, or deleting sensitive student and attendance data. The vulnerability requires valid admin credentials to exploit, but the attack itself is straightforward and exploit code is publicly available.
- CVE-2026-12789MEDIUM 4.7
ILIAS Learning Management System version 11.0 contains a SQL injection vulnerability in its Learning Progress Tracking component. An authenticated administrator can manipulate a parameter called troup_table_nav to inject malicious SQL commands, potentially allowing unauthorized data access or modification within the LMS database. The vulnerability requires administrative privileges to exploit and poses a medium-severity risk to institutions using this open-source learning platform.
- CVE-2026-13495MEDIUM 4.7
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the /adminprofile.php file. An attacker with administrative privileges can manipulate the loginid parameter to inject malicious SQL commands, potentially allowing unauthorized data access or modification. The vulnerability has been publicly disclosed and is remotely exploitable, though it requires high-level privileges to execute.
- CVE-2026-13569MEDIUM 4.7
A SQL injection vulnerability exists in EyouCMS versions up to 1.7.1, affecting the API endpoint at /index.php. An authenticated attacker can inject malicious SQL commands through the 'click_like' parameter to manipulate database queries. The vulnerability requires administrative or high-privilege credentials to exploit, but once triggered, allows an attacker to read, modify, or delete sensitive database records. Public exploit code is already available.
- CVE-2026-10661MEDIUM 4.3
A vulnerability in the blender-mcp project allows an authenticated attacker to inject malicious input through the input_image_url parameter in the Open function of src/blender_mcp/server.py. Because authentication is required and the vulnerability only exposes limited information (not enabling code execution or system availability impact), the overall risk is moderate. However, the public disclosure means exploitation techniques are now accessible to threat actors.
- CVE-2026-11511LOW 3.5
Bolt CMS versions up to 3.7.5 contain a vulnerability in how it handles HTML attributes within text fields. An authenticated attacker can manipulate the 'style' argument to inject arbitrary HTML code, potentially affecting the visual presentation or behavior of a web page. The vulnerability requires user interaction (a user must view the injected content) and authentication, limiting its immediate risk. However, because Bolt CMS is no longer actively maintained, affected organizations should plan transitions away from this platform.
- CVE-2026-12812LOW 3.5
Radware Cyber Controller versions up to 10.11.0 contain an HTML injection vulnerability in the HTML Report Generation component. An authenticated attacker can inject malicious HTML code that will be rendered in reports viewed by other users. While the vulnerability requires an existing login and user interaction to exploit, the public disclosure and lack of vendor response increase risk. The flaw allows manipulation of report content and appearance but does not enable direct data theft or system crashes.
- CVE-2026-57522LOW 3.5
Bitwarden Server versions before 2026.5.0 allow authenticated users to inject malicious JSON data into event integration outputs by manipulating their own display name. When an organization has configured integrations (such as webhooks to SIEM, Slack, Teams, or Datadog) that include user information in the payload, an attacker can set their display name to contain JSON special characters. This causes the server to render those characters into the integration payload without properly escaping them, allowing the attacker to insert fake data fields that appear legitimate to downstream systems. The vulnerability requires an authenticated account and knowledge that event integrations are in use, limiting its scope to internal threat actors or compromised user accounts.