CVE-2026-26700: SQL Injection
Published Mar 2, 2026
·Updated
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/editemployee.php.
Affected Software
2 affected components
Sourcecodester Personnel Property Equipment System
Jon-remus-sevellejo Personnel Property Equipment System=1.0
Event History
Mar 2, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 28, 58142
Event
via FIRST·12:29 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-26700?
CVE-2026-26700 is classified as a critical vulnerability due to its potential for SQL Injection in the Personnel Property Equipment System.
2
How do I fix CVE-2026-26700?
To fix CVE-2026-26700, ensure proper input validation and use prepared statements to mitigate SQL Injection risks.
3
What is the affected software for CVE-2026-26700?
CVE-2026-26700 affects version 1.0 of the Sourcecodester Personnel Property Equipment System.
4
What are the implications of CVE-2026-26700?
Exploitation of CVE-2026-26700 allows attackers to manipulate SQL queries, potentially gaining unauthorized access to sensitive data.
5
Is CVE-2026-26700 publicly known?
Yes, CVE-2026-26700 is publicly documented and should be addressed by organizations using the vulnerable software.