CVE-2026-2058General(vishalmathur / cloudclassroom-php-project)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Post Query Details Page. This manipulation of the argument gnamex causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.

1.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloudclassroom-php-project

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
cloudclassroom-php-project

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-06: 2PoC Mentioned / Linked · 2026-02-06: 1Technical Details · 2026-02-06: 102-06
Signal classification2 categories
General
150.0%
PoC
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-2058 A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquery… https://www.cve.org/CVERecord?id=CVE-2026-2058

    Post summary

    The post announces CVE‑2026‑2058 but provides no substantive details, exploit code, patch information, or evidence of active exploitation.

    00010167
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    PoC

    CVE-2026-2058 CLOUD-CLASSROOMS-php-1.0 PoC - Sql Injection Erro Based Presentation: Security vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2058

    Post summary

    The text announces a Proof of Concept for a SQL injection vulnerability in CLOUD-CLASSROOMS-php-1.0, with no mention of active exploitation or available patches.

    0000086
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvishalmathurcloudclassroom-php-project1.0--

Explore more