CVE-2026-13498Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. Such manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-28: 3Technical Details · 2026-06-28: 106-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-13498 A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POS… https://www.cve.org/CVERecord?id=CVE-2026-13498

    Post summary

    A new CVE (CVE‑2026‑13498) is noted for an unnamed function in the /forgotpassword.php file of a restaurant‑management system, with no further technical details, exploit, or remediation information provided.

    00010859
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13498 SQL Injection in yashpokharna2555 Restaurant-Management-System POST Parameter Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13498

    Post summary

    The post briefly announces a new SQL injection vulnerability in a restaurant‑management system, providing a link to detail the issue.

    00010134
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13498 A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POS… https://www.cve.org/CVERecord?id=CVE-2026-13498 ----- Traducción: CVE-2026-13498 Se … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑13498 for a restaurant‑management system, providing limited detail about the affected file but no evidence of exploits, mitigation, or active use.

    0000028
    89 followersView on X

Explore more