QSearchQSearch

CVE-2026-9544

7.3 HIGH

A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10

Published: 2026-05-26 · Last updated: 2026-05-26

Severity and scoring

CVSS
7.3 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE
CWE-74, CWE-89

Description

A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the file /api/Dinner/PayConfig. Performing a manipulation of the argument tableno results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-52715 Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions (9.3 CRITICAL)
  • CVE-2026-52712 Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions (7.6 HIGH)
  • CVE-2026-49772 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events C... (9.3 CRITICAL)
  • CVE-2026-39581 Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions (8.5 HIGH)
  • CVE-2026-39574 Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions (9.3 CRITICAL)