VYPR
Medium severity6.5NVD Advisory· Published Jul 1, 2026· Updated Jul 2, 2026

CVE-2026-51946

CVE-2026-51946

Description

SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive information via the the __sort_type URL parameter on all /admin/info/{table} endpoints

Affected products

2
  • GoAdminGroup/GoAdminllm-fuzzy2 versions
    <=1.2.26+ 1 more
    • (no CPE)range: <=1.2.26
    • (no CPE)range: <=1.2.26

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.