CVE-2026-7199Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_product. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-28); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-28: 3Mentions · 2026-06-05: 1Technical Details · 2026-04-28: 204-2806-05
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-283
Disclosure2General1
2026-06-051
Disclosure1
Full discourse4 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    💥 CVE-2026-7199 — A vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 affecting /ajax.php?action=delete_product allows SQL injection via manipulation of the ID argument. #CVE-2026-7199 #SourceCodester #PharmacySystem #SQLInjection #Vulnerability https://nvd.nist.gov/vuln/detail/CVE-2026-7199

    Post summary

    The post announces a new SQL injection vulnerability (CVE-2026-7199) in SourceCodester Pharmacy Sales and Inventory System 1.0, specifying the affected endpoint and parameter, but provides no PoC, exploit code, or patch information.

    2003052
    1.7K followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    New advisory to triage: CVE-2026-7199. A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown… Inventory first. Panic never helps.

    Post summary

    An advisory has been issued for CVE-2026-7199 affecting SourceCodester Pharmacy Sales and Inventory System 1.0, but the post lacks technical details, exploitation evidence, or mitigation guidance.

    1000043
    311 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7199 SQL Injection in SourceCodester Pharmacy Sales and Inventory System 1.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7199

    Post summary

    The post announces CVE‑2026‑7199 as a SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0, providing a link to further details.

    0000038
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7199 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7199 #CVE-2026-7199 #CVE #High #CyberSecurity #InfoSec https://t.co/Iq2R87BKIS

    Post summary

    The tweet announces CVE-2026-7199 with a severity rating but provides no details on exploitation, patching, or technical aspects.

    0000040
    142 followersView on X

Explore more