CVE-2026-5648Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /userfinishregister.php of the component Parameter Handler. This manipulation of the argument firstName causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-04-06); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-04-06: 5Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-06: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-06: 4Technical Details · 2026-04-28: 104-0604-28
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-065
Disclosure3General1Patch1
2026-04-281
Patch1
Full discourse6 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-5648 (CVSS 7.3) - SQL injection in Simple Laundry System 1.0 via /userfinishregister[.]php. Remote exploit published. Patch immediately if deployed. #CVE #Vulnerability #PatchNow #ThreatIntel

    Post summary

    The tweet reports a SQL injection vulnerability (CVE-2026-5648) that has a publicly released remote exploit and urges immediate patching.

    0101034
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5648 SQL Injection in Code-Projects Simple Laundry System 1.0 Parameter Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5648

    Post summary

    The text announces CVE-2026-5648, a SQL injection flaw in Code-Projects Simple Laundry System 1.0's parameter handler, without further details on exploitation or remediation.

    0100054
    4.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH severity CVE-2026-5648 (CVSS 7.3): SQL injection in Simple Laundry System 1.0 via /userfinishregister[.]php. Remote exploit published. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/yzLOkniTP7

    Post summary

    The tweet announces the high‑severity CVE‑2026‑5648, a SQL injection in Simple Laundry System 1.0, and urges an immediate patch after noting a published remote exploit.

    0000057
    27 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5648 - code-projects Simple Laundry System Parameter userfinishregister.php sql injection Intel Report: https://ift.tt/izXBZ4W

    Post summary

    The alert announces CVE‑2026‑5648 as an SQL injection vulnerability affecting the Simple Laundry System’s userfinishregister.php endpoint, with no evidence of active exploitation, patch, or PoC.

    0000036
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5648 A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /userfinishregister.php of the component Parameter… https://www.cve.org/CVERecord?id=CVE-2026-5648 ----- Traducción: CVE-2026-5648 Se … http://infoflow.cloud`

    Post summary

    The post reports the discovery of CVE‑2026‑5648 in Simple Laundry System 1.0, noting a flaw in the /userfinishregister.php file, but it offers no PoC, exploit code, patch information, or evidence of active exploitation.

    0000032
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5648 A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /userfinishregister.php of the component Parameter… https://www.cve.org/CVERecord?id=CVE-2026-5648

    Post summary

    The text announces a newly discovered vulnerability (CVE‑2026‑5648) in Simple Laundry System 1.0, noting its impact on the /userfinishregister.php file, but provides no further technical details or remediation.

    00000447
    57.0K followersView on X

Explore more