CVE-2026-1533Injection in Online Music Site

Severity
5.1MEDIUMNVD
EPSS
0.0%
top 97.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 28
Latest updateFeb 18

Description

A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminAddCategory.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
code-projects Online Music Site AdminAddCategory.php sql injection2026-01-28
GHSA
GHSA-6j3c-8fmm-47jq: A security flaw has been discovered in code-projects Online Music Site 12026-01-28

📋Vendor Advisories

1
Red Hat
kernel: bonding: annotate data-races around slave->last_rx2026-02-18
CVE-2026-1533 — Injection in Online Music Site | cvebase