A vulnerability labeled as critical has been found in jflyfox jfinal_cms up to 5.1.0. This impacts the function list of the file AdvicefeedbackController.java. Such manipulation of the argument orderBy leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-11473. The attack can be launched remotely. No exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability identified as critical has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /index1.php. This manipulation of the argument Password causes sql injection.
This vulnerability is handled as CVE-2026-11472. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability categorized as critical has been discovered in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /index2.php. The manipulation of the argument Password results in sql injection.
This vulnerability is known as CVE-2026-11471. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability was found in hs-web hsweb-framework up to 5.0.1. It has been rated as critical. The affected element is the function denied of the file hsweb-system/hsweb-system-file/src/main/java/org/hswebframework/web/file/FileUploadProperties.java of the component File Upload. The manipulation of the argument filename leads to path traversal.
This vulnerability is traded as CVE-2026-11470. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is suggested to install a patch to address this issue.
A vulnerability was found in jishenghua jshERP up to 3.6. It has been declared as critical. Impacted is the function insertPlatformConfig of the file jshERP-boot/src/main/java/com/jsh/erp/service/PlatformConfigService.java of the component platformConfig Add Endpoint. Executing a manipulation of the argument platformValue can lead to server-side request forgery.
This vulnerability appears as CVE-2026-11469. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in SourceCodester Hospitals Patient Records Management System 1.0. It has been classified as problematic. This issue affects some unknown processing of the file /admin/?page=room_types. Performing a manipulation of the argument room results in cross site scripting.
This vulnerability is reported as CVE-2026-11468. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability was found in jishenghua jshERP up to 3.6 and classified as critical. This vulnerability affects the function addAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component addAccountHeadAndDetail Endpoint. Such manipulation of the argument fileName leads to path traversal.
This vulnerability is documented as CVE-2026-11467. The attack can be executed remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability has been found in zilliztech deep-searcher up to 0.0.2 and classified as problematic. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls.
This vulnerability is registered as CVE-2026-11466. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The pull request to fix this issue awaits acceptance.