{"id":"CVE-2026-86168","title":"A security flaw has been discovered in code-projects Content Management System 1.0","summary":"A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can b…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-74","CWE-89"],"vendor":"code-projects","product":"Content Management System","affected":["content_management_system 1.0"],"published":"2026-09-06","updated":"2026-09-08","sourceUpdated":"2026-09-08T18:21:15.667","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86168","references":[{"url":"https://code-projects.org/","label":"cna@vuldb.com"},{"url":"https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/SQL%20Injection%20Vulnerability%20in%20Content%20Management%20System%20%60user_name%60%20Parameter.md","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-86168","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895608","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/399307","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/399307/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-08T17:03:08.409281Z"},"epss":0.00336,"epssPercentile":0.27144,"ingestedAt":"2026-09-06T16:57:43.715Z","slug":"CVE-2026-86168","body":"## Overview\n\nA security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":40.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":8314,"id":"CVE-2026-86168","ts":1788919997306,"field":"exploit_available","old":"false","new":"true"},{"seq":8123,"id":"CVE-2026-86168","ts":1788919286747,"field":"exploit_available","old":"true","new":"false"},{"seq":7932,"id":"CVE-2026-86168","ts":1788916358664,"field":"exploit_available","old":"false","new":"true"},{"seq":7741,"id":"CVE-2026-86168","ts":1788915304178,"field":"exploit_available","old":"true","new":"false"},{"seq":7550,"id":"CVE-2026-86168","ts":1788912719038,"field":"exploit_available","old":"false","new":"true"},{"seq":7359,"id":"CVE-2026-86168","ts":1788911336783,"field":"exploit_available","old":"true","new":"false"},{"seq":7163,"id":"CVE-2026-86168","ts":1788909080593,"field":"exploit_available","old":"false","new":"true"},{"seq":6975,"id":"CVE-2026-86168","ts":1788907393701,"field":"exploit_available","old":"true","new":"false"},{"seq":6777,"id":"CVE-2026-86168","ts":1788905446392,"field":"exploit_available","old":"false","new":"true"},{"seq":6595,"id":"CVE-2026-86168","ts":1788903460591,"field":"exploit_available","old":"true","new":"false"},{"seq":6381,"id":"CVE-2026-86168","ts":1788901812391,"field":"exploit_available","old":"false","new":"true"},{"seq":6211,"id":"CVE-2026-86168","ts":1788899562861,"field":"exploit_available","old":"true","new":"false"},{"seq":5974,"id":"CVE-2026-86168","ts":1788898181291,"field":"exploit_available","old":"false","new":"true"},{"seq":5863,"id":"CVE-2026-86168","ts":1788895711898,"field":"exploit_available","old":"true","new":"false"},{"seq":5691,"id":"CVE-2026-86168","ts":1788894534805,"field":"exploit_available","old":"false","new":"true"},{"seq":5649,"id":"CVE-2026-86168","ts":1788891871736,"field":"exploit_available","old":"true","new":"false"},{"seq":5621,"id":"CVE-2026-86168","ts":1788890901899,"field":"exploit_available","old":"false","new":"true"}]}