SQL Injection Vulnerability in Simple IT Discussion Forum by Code-Projects
CVE-2026-5672
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 6 April 2026
Badges
What is CVE-2026-5672?
The Simple IT Discussion Forum version 1.0 by Code-Projects contains a vulnerability in the edit-category.php file within its Parameter Handler component. This flaw allows for SQL injection, where manipulating the cat_id parameter can enable an attacker to execute malicious SQL queries remotely. As the exploit has been publicly disclosed, it poses a significant risk to users of this software if not patched. Organizations employing this product should take immediate steps to secure their installations against potential attacks.
Affected Version(s)
Simple IT Discussion Forum 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
