CVE-2026-88395: SQL Injection
Published Oct 5, 2026
·Updated
GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.
Affected Software
1 affected component
GouGuOA GouGuOA<=6.0.5
Event History
Oct 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are affected?
GouGuOA version 6.0.5 and earlier are identified as affected. The issue is in the /home/message/rubbish endpoint when it processes the keywords parameter.
2
What input is associated with exploitation?
The vulnerability is an SQL injection condition involving the keywords parameter sent to /home/message/rubbish. The provided data does not specify authentication requirements, required privileges, or a known exploit path.