CVE-2026-5134: SQLi in Loca Software's CMS
Published Aug 6, 2026
·Updated
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection.
This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
1 affected component
CMS<=06082026
Event History
Aug 6, 2026
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-5134?
The severity of CVE-2026-5134 is critical with a CVSS score of 9.8.
2
What type of vulnerability is CVE-2026-5134?
CVE-2026-5134 is an SQL injection vulnerability affecting Loca Software's CMS.
3
How do I fix CVE-2026-5134?
To fix CVE-2026-5134, validate and sanitize user inputs to prevent SQL injection.
4
Which CMS version is affected by CVE-2026-5134?
CVE-2026-5134 affects Loca Software's CMS through version 06082026.
5
What are the potential impacts of CVE-2026-5134?
CVE-2026-5134 can allow attackers to compromise the database, resulting in data loss or corruption.