SQL Injection Vulnerability in Projectworlds Online Art Gallery Shop
CVE-2026-3757
Key Information:
- Vendor
Projectworlds
- Status
- Vendor
- CVE Published:
- 8 March 2026
Badges
What is CVE-2026-3757?
A security flaw present in Projectworlds' Online Art Gallery Shop version 1.0 exposes the application to SQL injection attacks via the /?pass=1 endpoint. By manipulating the input parameter 'fnm', an attacker can execute unauthorized SQL queries. This type of vulnerability permits attackers to launch their exploits remotely, potentially compromising the integrity and confidentiality of the data stored within the application. Publicly available exploit details heighten the urgency for remediation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Online Art Gallery Shop 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
