CVE-2026-0567

HIGH

Code-projects Content Management System - Injection

Title source: rule

Description

A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

Scores

CVSS v3 7.3
EPSS 0.0004
EPSS Percentile 10.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-89 CWE-74
Status published

Affected Products (1)

code-projects/content_management_system

Timeline

Published Jan 02, 2026
Tracked Since Feb 18, 2026