← Back to overview

A SQL injection vulnerability (CVE-2026-18210) has been identified in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company's 'Products Store' application. The vulnerability is classified as an improper neutralization of special elements used in SQL commands, allowing attackers to perform SQL injection attacks. All versions of Products Store prior to commit 030631b2 are affected. The vulnerability was reported via the Turkish cybersecurity authority (siberguvenlik.gov.tr) and published on the NVD. Exploitation could allow unauthorized access to or manipulation of the underlying database. Users are advised to update to a version at or after commit 030631b2 to remediate the issue.

Affected products

  • TRtek Products Store (before 030631b2)

Related CVE's

  • CVE-2026-18210

Categories

  • Database & Storage
  • Web Technologies