CVE-2026-86168: code-projects Content Management System login.php sql injection
A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument username results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What deployment conditions make an instance exposed?
Code-projects Content Management System 1.0 is affected where its /login.php endpoint is reachable over the network. The vulnerable input is the user_name argument.
Does an attacker need an account or user interaction to exploit this issue?
No. The supplied vector indicates network-based exploitation with no privileges and no user interaction required.
How likely is active exploitation?
A public exploit has been released and may be used in attacks. Prioritize review of requests to /login.php, especially user_name values that may indicate SQL injection attempts.