← Back to overview

A SQL injection vulnerability has been identified in code-projects Content Management System version 1.0. The flaw exists in the /login.php file where manipulation of the user_name parameter allows SQL injection attacks. The vulnerability can be exploited remotely without authentication. A public exploit has already been released, increasing the risk of active exploitation. The issue stems from insufficient input validation on the user_name argument. Attackers could potentially bypass authentication or extract sensitive database information. The vulnerability has been assigned CVE-2026-86168 and is listed in the NVD database. Users of the affected CMS version are advised to apply patches or mitigations immediately.

Affected products

  • code-projects Content Management System 1.0

Related CVE's

  • CVE-2026-86168

Categories

  • Database & Storage
  • Identity & Access
  • Web Technologies