A vulnerability, which was classified as critical, was found in projectworlds Online Art Gallery Shop 1.0. This affects an unknown part of the file /admin/adminHome.php. Such manipulation of the argument reach_nm leads to sql injection.
This vulnerability is documented as CVE-2026-3759. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability, which was classified as critical, has been found in projectworlds Online Art Gallery Shop 1.0. Affected by this issue is some unknown functionality of the file /admin/adminHome.php. This manipulation of the argument Info causes sql injection.
This vulnerability is registered as CVE-2026-3758. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability classified as critical was found in projectworlds Online Art Gallery Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /?pass=1. The manipulation of the argument fnm results in sql injection.
This vulnerability is cataloged as CVE-2026-3757. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical has been found in SourceCodester Sales and Inventory System up to 1.0. Affected is an unknown function of the file /check_item_details.php. The manipulation of the argument stock_name1 leads to sql injection.
This vulnerability is listed as CVE-2026-3756. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability described as critical has been identified in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /check_customer_details.php of the component POST Handler. Executing a manipulation of the argument stock_name1 can lead to sql injection.
This vulnerability is tracked as CVE-2026-3755. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability marked as critical has been reported in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /add_stock.php. Performing a manipulation of the argument cost results in sql injection.
This vulnerability is identified as CVE-2026-3754. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability labeled as critical has been found in SourceCodester Sales and Inventory System up to 1.0. The impacted element is an unknown function of the file /add_sales_print.php. Such manipulation of the argument sid leads to sql injection.
This vulnerability is referenced as CVE-2026-3753. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability identified as critical has been detected in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown function of the file /daily-task-report.php of the component GET Parameter Handler. This manipulation of the argument Date causes sql injection.
The identification of this vulnerability is CVE-2026-3752. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability categorized as critical has been discovered in SourceCodester Employee Task Management System 1.0. Impacted is an unknown function of the file /daily-attendance-report.php of the component GET Parameter Handler. The manipulation of the argument Date results in sql injection.
This vulnerability was named CVE-2026-3751. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability was found in ContiNew Admin up to 4.2.0. It has been rated as critical. This issue affects the function URI.create of the file continew-system/src/main/java/top/continew/admin/system/factory/S3ClientFactory.java of the component Storage Management Module. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-3750. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.