CVE-2026-8128General

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the file /admin/viewmsg.php. Performing a manipulation of the argument msgid results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-08); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-08: 2Mentions · 2026-05-10: 1Mentions · 2026-06-16: 1Technical Details · 2026-05-08: 1Technical Details · 2026-06-16: 105-0805-1006-16
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-082
Disclosure1General1
2026-05-101
General1
2026-06-161
General1
Full discourse4 posts
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    General

    CVE-2026-8128 is a good patch-discipline check. exploit / SQL injection. Public details are enough to start scoping. Where does this show up in your environment?

    Post summary

    The text references CVE-2026-8128 as a SQL injection vulnerability with publicly available details, but does not provide a PoC, exploit, or active exploitation evidence.

    1000038
    337 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-8128 A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the file /admin/viewmsg.php. Performing a manipulati… https://www.cve.org/CVERecord?id=CVE-2026-8128

    Post summary

    The statement merely reports the existence of CVE-2026-8128 in SourceCodester SUP Online Shopping 1.0, offering only a file path and no further actionable details.

    00010113
    57.5K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-8128 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-8128 #CVE-2026-8128 #CVE #High #CyberSecurity #InfoSec https://t.co/tarBFKIXQD

    Post summary

    The post announces CVE-2026-8128 with a 7.3 severity rating but offers no technical details, exploitation evidence, or remediation guidance.

    0000035
    157 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-8128 A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the… CVSS 7.3 Full analysis → https://sec.kaitan.id/cves/CVE-2026-8128 #HP #CyberSecurity #InfoSec

    Post summary

    The notice announces CVE‑2026‑8128 with basic technical details and a CVSS score, but no PoC, exploit code, active exploitation, or patch is mentioned.

    0000039
    515 followersView on X

Explore more