High severityNVD Advisory· Published Aug 27, 2026
CVE-2026-81676
CVE-2026-81676
Description
A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the limit_videos parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL syntax errors and potentially manipulate backend queries. The issue results in an error-based SQL injection and exposes internal database error messages and stack traces, revealing implementation details of the backend system.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.