CVE-2026-1142
published 2026-01-19CVE-2026-1142: A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.20%
9.6th percentile
A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlientems | — | — |
| fortinet | fortinet | — | — |
| phpgurukul | news_portal | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w98p-2mg7-6p5x: A security flaw has been discovered in PHPGurukul News Portal 1
ghsa_unreviewed·2026-01-19
CVE-2026-1142 [MEDIUM] CWE-352 GHSA-w98p-2mg7-6p5x: A security flaw has been discovered in PHPGurukul News Portal 1
A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
CISA
Fortinet SQL Injection Vulnerability
cisa·2026-04-13·CVSS 9.8
CVE-2026-21643 [CRITICAL] CWE-89 Fortinet SQL Injection Vulnerability
Vulnerability: Fortinet SQL Injection Vulnerability
Affected: Fortinet FortiClient EMS
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-1142 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21643
Remediation Due Date: 2026-04-16
Fortinet
SQLi in administrative interface
vendor_fortinet·2026-02-06·CVSS 9.8
CVE-2026-21643 [CRITICAL] CWE-89 SQLi in administrative interface
FG-IR-25-1142: SQLi in administrative interface
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVEs: CVE-2026-21643
CWEs: CWE-89
CVSS: 9.8 (critical)
Affected products: FortiClientEMS, FortiClientems, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-01-19
Published