CVE-2026-4540General

LOWCVSS 5.5 · MEDIUM

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processing of the file /login.php of the component Parameters Handler. The manipulation of the argument User results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 4 classified signals
  • Disclosure: 1 classified signal
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-22: 5Technical Details · 2026-03-22: 203-22
Signal classification2 categories
General
480.0%
Disclosure
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4540 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4540 #CVE-2026-4540 #CVE #High  #CyberSecurity #InfoSec https://t.co/xwbzXxIb5m

    Post summary

    The tweet merely announces the existence of CVE-2026-4540, providing its severity and a link to the NVD entry.

    0000018
    111 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4540 - projectworlds - Online Notes Sharing System - https://www.redpacketsecurity.com/cve-alert-cve-2026-4540-projectworlds-online-notes-sharing-system/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4540 #projectworlds #online-notes-sharing-system

    Post summary

    The tweet announces a CVE alert for ProjectWorlds but provides no substantive technical details, exploitation evidence, or mitigation information.

    0000069
    3.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4540 - projectworlds Online Notes Sharing System Parameters login.php sql injection Intel Report: https://ift.tt/hmAlDLW

    Post summary

    The alert highlights CVE-2026-4540 as a SQL injection in projectworlds login.php, but offers no proof of concept, exploit code, or evidence of active exploitation.

    0000021
    292 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4540 SQL Injection in projectworlds Online Notes Sharing System 1.0 via Login Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4540

    Post summary

    The post discloses CVE-2026-4540, an SQL injection flaw in ProjectWorlds Online Notes Sharing System 1.0, but offers no PoC, exploit code, or patch information.

    0000036
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4540 A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processing of the file /login.php of the component Parame… https://www.cve.org/CVERecord?id=CVE-2026-4540

    Post summary

    A brief CVE record for CVE-2026-4540 references an issue in Projectworlds Online Notes Sharing System 1.0 affecting /login.php, but provides no further details.

    0000059
    56.8K followersView on X

Explore more