CVE-2026-7070Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in code-projects Inventory Management System 1.0. Affected is an unknown function of the component Login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-27: 3Technical Details · 2026-04-27: 104-27
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7070 A weakness has been identified in code-projects Inventory Management System 1.0. Affected is an unknown function of the component Login. Executing a manipulation of the… https://www.cve.org/CVERecord?id=CVE-2026-7070

    Post summary

    A weakness was reported in Inventory Management System 1.0 affecting an unknown Login function, but no additional exploit, patch, or technical details were provided.

    0000097
    57.3K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7070 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7070 #CVE-2026-7070 #CVE #High #CyberSecurity #InfoSec https://t.co/TmYg1KRPxC

    Post summary

    A brief tweet announcing CVE‑2026‑7070 with a severity of 7.3, offering no details on exploits, patches, or technical nature.

    0000056
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7070 SQL Injection in Code-Projects Inventory Management System 1.0 Login https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7070

    Post summary

    A SQL injection vulnerability was disclosed in the Code-Projects Inventory Management System 1.0 login page. No PoC, exploit code, or active exploitation is reported.

    0000046
    4.0K followersView on X

Explore more