CVE-2026-3759

CRITICAL WAF: High
CVSS 9.8 Published: 2026-03-08
CWE-89

A security vulnerability has been detected in projectworlds Online Art Gallery Shop 1.0. This affects an unknown part of the file /admin/adminHome.php. Such manipulation of the argument reach_nm leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

WAF Coverage Analysis

SQL Injection High WAF Coverage

OWASP: A03:2021 Injection

942xxx - SQL Injection

Affected Software

VendorProductVersion
projectworldsonline_art_gallery_shop1.0

References

  • github.com (Exploit, Issue Tracking, Third Party Advisory)
  • vuldb.com (Permissions Required, Third Party Advisory, VDB Entry)
  • vuldb.com (Third Party Advisory, VDB Entry)
  • vuldb.com (Third Party Advisory, VDB Entry)
Back to CVE Database