CVE-2026-66680
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
CVSS
9.3
Critical
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Aug 20, 2026 · Last modified: Aug 20, 2026 · CWE-89
0.3%EPSS · 30 days0.3%
2026-08-212026-09-06
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-865186.3 MED—
———A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.3hCVE-2026-865176.3 MED—
———A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.3hCVE-2026-447666.5 MED—
———SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.6hCVE-2026-863106.3 MED—
———A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.17hCVE-2026-863096.3 MED—
———A flaw has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.17hCVE-2026-862987.3 HIG—
——0A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.20h