CVE-2026-0851
Last modified
CVE-2026-0851 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. The manipulation of the argument txtusername leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fabian | Online Music Site | 1.0 |
References
- https://code-projects.org/Product
- https://github.com/tuo159515/sql-injection/issues/2Exploit, Issue Tracking
- https://vuldb.com/?ctiid.340446Permissions Required, VDB Entry
- https://vuldb.com/?id.340446Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.733644Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-0851?
How severe is CVE-2026-0851?
How do I fix CVE-2026-0851?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-0845The WCFM – Frontend Manager for WooCommerce along with Booki…7.2
- CVE-2026-0846A vulnerability in the `filestring()` function of the `nltk.…7.5
- CVE-2026-0847A vulnerability in NLTK versions up to and including 3.9.2 a…7.5
- CVE-2026-0848NLTK versions <=3.9.2 are vulnerable to arbitrary code execu…10
- CVE-2026-0849Malformed ATAES132A responses with an oversized length field…6.8
- CVE-2026-0850A vulnerability was determined in code-projects Intern Membe…7.2
- CVE-2026-0852A security flaw has been discovered in code-projects Online …9.8
- CVE-2026-0853Certain NVR models developed by A-Plus Video Technologies ha…6.9
- CVE-2026-0854Certain DVR/NVR models developed by Merit LILIN has a OS Com…8.8
- CVE-2026-0855Certain IP Camera models developed by Merit LILIN has a OS C…8.8
- CVE-2026-0856Improper Access Control vulnerability in Mesalvo MEONA (MEON…7.8
- CVE-2026-0857Use of a Password Hash With Insufficient Computational Effor…4.4
Are you affected by CVE-2026-0851?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
