CVE-2026-6202
published 2026-04-13CVE-2026-6202: A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of…
PriorityP340medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.20%
9.5th percentile
A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | easy_blog_site | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mjj7-5jqv-3ff6: A security flaw has been discovered in code-projects Easy Blog Site 1
ghsa_unreviewed·2026-04-13
CVE-2026-6202 [MEDIUM] CWE-74 GHSA-mjj7-5jqv-3ff6: A security flaw has been discovered in code-projects Easy Blog Site 1
A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
VulDB
code-projects Easy Blog Site 1.0 post.php tags sql injection
vuldb·2026-04-13·CVSS 5.3
CVE-2026-6202 [MEDIUM] code-projects Easy Blog Site 1.0 post.php tags sql injection
A vulnerability marked as critical has been reported in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection.
This vulnerability was named CVE-2026-6202. The attack may be initiated remotely. In addition, an exploit is available.
No detection rules found.
No public exploits indexed.
2026-04-13
Published