#Web Application Security
All CosmicBytez Labs articles tagged #Web Application Security, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-100314: SQL Injection in CloudClassroom-PHP-Project Student Details Update
CloudClassroom-PHP-Project is vulnerable to remote SQL injection via the eno parameter in updatedetailsfromstudent.php; the vendor has not responded.
- Security
CVE-2026-100315: SQL Injection in CloudClassroom-PHP-Project Faculty Details Lookup
CloudClassroom-PHP-Project is vulnerable to remote SQL injection via the myfid parameter in mydetailsfaculty.php; a public PoC exploit exists.
- Security
CloudClassroom-PHP-Project viewresult.php SQL Injection (CVE-2026-100739)
An unpatched SQL injection in CloudClassroom-PHP-Project's viewresult.php lets remote attackers manipulate the seno parameter to steal data.
- Security
CVE-2026-56736: phpMyFAQ Stored XSS via Admin Review
Unauthenticated users can plant stored XSS in phpMyFAQ FAQ submissions that executes in an admin's browser on review, enabling session theft.
- Security
CVE-2026-90854: SQL Injection in SourceCodester Online Food Ordering System
SourceCodester's Online Food Ordering System 1.0 is vulnerable to remote SQL injection via the ID parameter in category-foods.php; a public exploit exists.
- Security
CVE-2026-15981: WordPress SAML SSO Authentication Bypass (CVSS 9.8)
A critical authentication bypass in the WordPress SAML Single Sign On plugin allows unauthenticated attackers to log in as any user, including...
- Security
CVE-2026-16227: SQL Injection in SourceCodester Class and Exam Timetabling System
A remotely exploitable SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows unauthenticated attackers to manipulate...
- Security
CVE-2026-16228: SQL Injection in SourceCodester Class and Exam Timetabling System via edit_schoolyr.php
A second SQL injection flaw in SourceCodester Class and Exam Timetabling System 1.0 exposes the /edit_schoolyr.php endpoint to remote unauthenticated...
- Security
CVE-2026-13550: SQL Injection in itsourcecode Baptism Information Management System 1.0
A high-severity SQL injection vulnerability has been identified in itsourcecode Baptism Information Management System 1.0, allowing remote attackers to...
- Security
CVE-2026-13551: SQL Injection in itsourcecode Baptism Information Management System 1.0 (editBaptism.php)
A second high-severity SQL injection vulnerability has been disclosed in itsourcecode Baptism Information Management System 1.0, this time affecting the...
- Security
CVE-2026-48907: Joomla Content Editor Unauthenticated PHP Upload Flaw
A maximum-severity improper access control flaw in Widget Factory's Joomla Content Editor allows unauthenticated attackers to upload and execute arbitrary...
- News
Hackers Exploit React2Shell in Automated Credential Theft
Threat actors are running a large-scale, automated campaign exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js applications to steal...
- News
LexisNexis Confirms Cloud Breach Exposing 400K User
LexisNexis Legal & Professional confirms a data breach after threat actor FulcrumSec exploited an unpatched React2Shell vulnerability to exfiltrate 2.04...