CVE-2026-66478
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
CVSS
9.3
Crítico
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Publicado: 13 ago 2026 · Última mod.: 14 ago 2026 · CWE-89
0.3%EPSS · 30 días0.3%
2026-08-142026-09-05
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-862207.3 ALT—
———A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.3hCVE-2026-196346.4 MED—
———PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later5hCVE-2026-196338.8 ALT—
———PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions5hCVE-2026-862137.3 ALT—
———A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_name/book_author results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.8hCVE-2026-862117.3 ALT—
——0A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.10hCVE-2026-862107.3 ALT—
——0A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.11h