High severity7.3NVD Advisory· Published Mar 2, 2026· Updated Apr 29, 2026
CVE-2026-3406
CVE-2026-3406
Description
A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected products
1- cpe:2.3:a:projectworlds:online_art_gallery_shop:1.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/ubfbuz3/cve/issues/55nvdExploitThird Party AdvisoryIssue Tracking
- vuldb.comnvdExploitThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
News mentions
0No linked articles in our index yet.