CVE-2026-90496Medium· 4.7▾ TwilightPoC availableA vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handle…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 25.9 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Exploit / PoC code exists
A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handlers. Performing a manipulation of the argument modules/dims results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90495High· 7.3A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11
CVE-2026-90497Low· 3.5A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11
CVE-2023-4548Medium· 6.3A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3
CVE-2025-9236Medium· 6.3A vulnerability has been found in Portabilis i-Educar up to 2.10
CVE-2025-9606Medium· 6.3A vulnerability was detected in Portabilis i-Educar up to 2.10
CVE-2025-9531Medium· 6.3A vulnerability was detected in Portabilis i-Educar up to 2.10