CVE-2026-73640Critical· 9.3▾ MidnightDayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73641Medium· 5.1Dayforce Payroll is vulnerable to Reflected XSS in multiple endpoints
CVE-2026-73642Critical· 9.2Dayforce Payroll is vulnerable to Path Traversal in file download functionality
CVE-2025-14666High· 7.3A weakness has been identified in itsourcecode COVID Tracking System 1.0
CVE-2025-14667High· 7.3A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0
CVE-2025-14668High· 7.3A vulnerability was detected in campcodes Advanced Online Examination System 1.0
CVE-2025-14664High· 7.3A vulnerability was identified in Campcodes Supplier Management System 1.0