CVE-2026-19344: code-projects Task Management System comment_count_user.php sql injection
Published Aug 9, 2026
·Updated
A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/commentcountuser.php. The manipulation of the argument taskid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
code-projects Task Management System=1.0
Event History
Aug 9, 2026
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19344?
CVE-2026-19344 has a severity rating of high with a score of 7.3.
2
What type of vulnerability is CVE-2026-19344?
CVE-2026-19344 is classified as an SQL injection vulnerability.
3
How do I fix CVE-2026-19344?
To fix CVE-2026-19344, sanitize and validate the input parameters, particularly the task_id argument in the comment_count_user.php file.
4
Can CVE-2026-19344 be exploited remotely?
Yes, CVE-2026-19344 can be exploited remotely.
5
Which software is affected by CVE-2026-19344?
CVE-2026-19344 affects code-projects Task Management System version 1.0.