CVE-2026-11490 - SQLi in code-projects Online Music Site 1.0. /Frontend/Search.php Category param. Remote attack, public exploit. CVSS 7.3. No patch available. Mitigate immediately. #CVE #infosec #SQLi

https://www.valtersit.com/cve/CVE-2026-11490/

CVE-2026-11490 | Code-projects | Valters IT Hub

A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This ma...

Valters IT Hub

CVE-2026-11334 - SQL injection in Tittuvarghese CollegeManagementSystem. Remote exploit via department_code parameter. CVSS 7.3. Public exploit available. Update immediately if using this software. #CVE #infosec #SQLi

https://www.valtersit.com/cve/CVE-2026-11334/

CVE-2026-11334 | Tittuvarghese | Valters IT Hub

A vulnerability was detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Th...

Valters IT Hub
๐Ÿ›ก๏ธ CRITICAL: CVE-2026-45779 in Open XDMoD < 10.0.3 enables unauthenticated SQL injection โ€” total DB compromise possible! Patch to 10.0.3+ or apply manual fix. No known exploitation yet. Details: https://radar.offseq.com/threat/cve-2026-45779-cwe-89-improper-neutralization-of-s-cff49bf0 #OffSeq #Vuln #SQLi #HPC

๐Ÿ“ฐ Critical Ghost CMS Flaw (CVE-2026-26980) Exploited to Inject Malware on 700+ Sites

๐Ÿ“ข GHOST CMS HACKED: A critical SQL injection flaw (CVE-2026-26980) is being mass-exploited to hack Ghost sites. Attackers steal API keys to inject malware that targets visitors. Over 700 sites hit. Patch and rotate keys NOW! #GhostCMS #CVE #SQLi

๐ŸŒ cyber[.]netsecops[.]io

๐Ÿ”— https://cyber.netsecops.io/articles/ghost-cms-flaw-cve-2026-26980-exploited-to-inject-malware/?utm_source=mastoโ€ฆ

๐Ÿ“ฐ Critical Unauthenticated SQLi Flaw in Drupal Core Hits PostgreSQL Sites

๐Ÿšจ CRITICAL vulnerability in Drupal Core (CVE-2026-9082)! Unauthenticated SQL injection affects sites using PostgreSQL, allowing for potential RCE. Patch immediately! #Drupal #CyberSecurity #SQLi #Vulnerability

๐ŸŒ cyber[.]netsecops[.]io

๐Ÿ”— https://cyber.netsecops.io/articles/critical-sql-injection-vulnerability-cve-2026-9082-in-drupal-core-for-postgresql/?utm_source=mastodon&utm_medium=social&utm_campaign=daily

๐Ÿ“ฐ Critical Unauthenticated SQLi Flaw in Drupal Core Hits PostgreSQL Sites

๐Ÿšจ CRITICAL vulnerability in Drupal Core (CVE-2026-9082)! Unauthenticated SQL injection affects sites using PostgreSQL, allowing for potential RCE. Patch immediately! #Drupal #CyberSecurity #SQLi #Vulnerability

๐ŸŒ cyber[.]netsecops[.]io

๐Ÿ”— https://cyber.netsecops.io/articles/critical-sql-injection-vulnerability-cve-2026-9082-in-drupal-core-for-postgresql/?utm_source=mastodon&utm_medium=social&utm_campaign=daily

Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw

Hackers are targeting sensitive information stored in the LiteLLM open-source large-language model (LLM) gateway by exploiting a critical vulnerability  tracked as CVE-2026-42208.

BleepingComputer
MEDIUM severity: CVE-2026-7028 impacts CodeAstro Online Job Portal 1.0. SQL injection possible via /admin/jobs-admins/delete-jobs.php (ID param). Exploit is public โ€” monitor for attacks and restrict access! https://radar.offseq.com/threat/cve-2026-7028-sql-injection-in-codeastro-online-jo-7d79de51 #OffSeq #SQLi #Vulnerability #InfoSec
๐Ÿšจ CRITICAL: CyferShepard Jellystat <1.1.10 vulnerable to SQL injection (CVE-2026-41167). Authโ€™d users can read any DB table & execute commands on the PostgreSQL host. Upgrade to 1.1.10 ASAP! https://radar.offseq.com/threat/cve-2026-41167-cwe-89-improper-neutralization-of-s-51b08aed #OffSeq #Jellystat #SQLi #Infosec
๐Ÿšจ CRITICAL SQL injection (CVE-2026-37749) in CodeAstro Simple Attendance Management System v1.0: Remote unauthenticated attackers can bypass authentication via index.php. Restrict access & deploy WAFs until a patch arrives. https://radar.offseq.com/threat/cve-2026-37749-na-c4c6e5dc #OffSeq #SQLi #Infosec