QSearchQSearch

CVE-2026-10262

7.3 HIGH

A vulnerability has been found in code-projects Real State Services 1.0

Published: 2026-06-01 · Last updated: 2026-06-01

Severity and scoring

CVSS
7.3 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE
CWE-74, CWE-89

Description

A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-52700 Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions (8.5 HIGH)
  • CVE-2026-52697 Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions (8.5 HIGH)
  • CVE-2026-52693 Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions (9.3 CRITICAL)
  • CVE-2026-49776 Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 vers... (9.3 CRITICAL)
  • CVE-2026-49067 Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions (9.3 CRITICAL)