CVE-2026-5646Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Exploit: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-04-06); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-04-06: 5Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-06: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-06: 3Technical Details · 2026-04-28: 104-0604-28
Signal classification3 categories
Disclosure
466.7%
Exploit
116.7%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-065
Disclosure3Exploit1General1
2026-04-281
Disclosure1
Full discourse6 posts
  • DFIR Lab@DFIR_Lab
    Exploit

    🚨 HIGH: CVE-2026-5646 - CVSS 7.3 SQL Injection in code-projects Easy Blog Site 1.0 (login[.]php). Remotely exploitable, no auth required. Public exploit available. Patch immediately or disable affected instances. #CVE #Vulnerability #PatchNow #ThreatIntel

    Post summary

    CVE-2026-5646 is a significant SQL Injection flaw with a publicly available exploit; patching or disabling the affected site is urgently recommended.

    0101038
    1 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    🚨 HIGH: CVE-2026-5646 (CVSS 7.3) - SQL Injection in code-projects Easy Blog Site 1.0 (login[.]php). Remotely exploitable, no auth required. Public exploit available. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/7B5w1vnUT3

    Post summary

    The tweet announces a high‑severity SQL injection vulnerability (CVE‑2026‑5646) in Easy Blog Site 1.0, notes that a public exploit exists, and urges immediate patching.

    0000047
    27 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5646 SQL Injection in Code-Projects Easy Blog Site 1.0 Login Functionality https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5646

    Post summary

    CVE-2026-5646 is disclosed as a SQL injection flaw in Code-Projects Easy Blog Site 1.0 login function, with no PoC, exploit, or patch details referenced.

    0000054
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5646 - code-projects Easy Blog Site login.php sql injection Intel Report: https://ift.tt/RnPJ5Uc

    Post summary

    An alert is issued for CVE-2026-5646, an SQL injection vulnerability in code-projects Easy Blog Site login.php, with a link to the Intel Report.

    0000038
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5646 A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipula… https://www.cve.org/CVERecord?id=CVE-2026-5646 ----- Traducción: CVE-2026-5646 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-5646, noting a vulnerability in Easy Blog Site 1.0’s login.php, but provides no further exploitation or mitigation details.

    0000035
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5646 A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipula… https://www.cve.org/CVERecord?id=CVE-2026-5646

    Post summary

    A brief CVE-2026-5646 notice for Easy Blog Site 1.0 mentioning an undefined issue in login.php, with no further technical or exploit details provided.

    00000247
    57.0K followersView on X

Explore more