VulnerabilityAnalyzed
CVE-2026-0546
A vulnerability was determined in code-projects Content Management System 1.0.
MEDIUM 5.5EPSS 0.45%
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was determined in code-projects Content Management System 1.0. This impacts an unknown function of the file search.php. This manipulation of the argument Value causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
- CVSS 4.0
- 5.5 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- code-projects/content management system
- Source
- cna@vuldb.com
References
- https://code-projects.org/Product
- https://github.com/gtxy114514/CVE/issues/1Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.339338Permissions Required, VDB Entry
- https://vuldb.com/?id.339338Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.728924Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.