CVE-2026-14755Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. The manipulation of the argument delete leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-05: 3Patch / Workaround · 2026-07-05: 1Technical Details · 2026-07-05: 107-05
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH SEVERITY: CVE-2026-14755 (CVSS 7.3) SQL Injection in Hotel and Tourism Reservation 1.0 (/admin/reservations[.]php). Remotely exploitable, exploit publicly available. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/oBA5nX7ILw

    Post summary

    The tweet announces a new high‑severity SQL Injection flaw (CVE‑2026‑14755) in Hotel and Tourism Reservation 1.0, notes that it is remotely exploitable with a publicly available exploit, and urges users to patch immediately.

    0000056
    61 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14755 A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reser… https://www.cve.org/CVERecord?id=CVE-2026-14755 ----- Traducción: Se ha encontrado u… http://infoflow.cloud`

    Post summary

    The post announces the discovery of CVE‑2026‑14755 affecting a hotel reservation system, references the CVE record, but provides no PoC, exploit, patch, or detailed technical or active‑exploitation information.

    0000030
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-14755 A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reser… https://www.cve.org/CVERecord?id=CVE-2026-14755

    Post summary

    A brief announcement of CVE-2026-14755, noting it affects an unknown functionality in /admin/reser of the Hotel and Tourism Reservation 1.0 application, with no additional technical or practical details provided.

    000001.2K
    57.7K followersView on X

Explore more