CVE-2026-38468
A SQL injection vulnerability in the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18
CVSS
4.3
Medium
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Aug 25, 2026 · Last modified: Aug 31, 2026 · CWE-89
0.3%EPSS · 30 days0.4%
2026-08-262026-09-22
A SQL injection vulnerability in the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users with users_view_ips privileges to execute arbitrary SQL commands via the ip parameter in a crafted request to tools.php?action=get_cc.
- github.comhttps://github.com/Mosasauroidea/GazellePW/blob/86c4bedf727691b5a97af42a4864869d18446449/classes/tools.class.php#L22
- github.comhttps://github.com/Mosasauroidea/GazellePW/blob/86c4bedf727691b5a97af42a4864869d18446449/sections/tools/services/get_cc.php
- snaacky.comhttps://snaacky.com/1-click-exploit-chain-for-complete-gazellepw-database-compromise
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-756829.9 CRI—
——0Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.5hCVE-2026-820119.1 CRI—
——0Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction. Scope is changed.6hCVE-2026-820109.9 CRI—
——0Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.6hCVE-2026-820099.1 CRI—
——0Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary SQL commands. Exploitation of this issue does not require user interaction. Scope is changed.6hCVE-2026-651288.8 HIG—
——0NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.5hCVE-2026-127189.8 CRI—
——0Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection.
This issue affects KarelIPS: through 22092026.
NOTE: The vendor was contacted and it was learned that the product is not supported.6h