CVE-2026-108100Medium· 6.5▾ SunlitHortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in incl…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10079High· 7.3A flaw has been found in PHPGurukul Small CRM 4.0
CVE-2025-10405High· 7.3A vulnerability was determined in itsourcecode Baptism Information Management System 1.0
CVE-2025-10479High· 7.3A security flaw has been discovered in SourceCodester Online Student File Management System 1.0
CVE-2025-10387Medium· 6.3A vulnerability was determined in codesiddhant Jasmin Ransomware up to 1.0.1
CVE-2025-10068High· 7.3A flaw has been found in itsourcecode Online Discussion Forum 1.0
CVE-2025-10601High· 7.3A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0