
🚨 Free Hotel SQLi CVSS: 9.8 Unauthenticated DB access through login bypass flaws in Free Hotel CMS. Enables data exfiltration of user records and full backend takeover without auth. https://nvd.nist.gov/vuln/detail/CVE-2026-4966
Post summary
The post announces CVE-2026-4966 as a high‑severity SQL injection flaw in Free Hotel CMS that permits unauthenticated database access, data exfiltration, and full backend takeover, but it provides no PoC or evidence of active exploitation.



