Junglewise Threat Intelligence

CVE-2026-5805: code-projects Easy Blog Site SQL injection in contact_us.php

CVE-2026-5805 · Severity: high · CVSS 7.3 · Published 2026-04-08

Vendors: Code-Projects.

Executive brief

Easy Blog Site is a web application used for managing blog content. A security vulnerability in the contact form allows remote attackers to interfere with the site's database. This could lead to unauthorized access to information or disruption of the website's operations.

Technical details

A SQL injection vulnerability exists in code-projects Easy Blog Site version 1.0. The flaw is located within the /users/contact_us.php component, where the 'Name' argument is not properly sanitized before being used in a database query. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to manipulate SQL commands. This can result in unauthorized data retrieval, modification, or deletion. A public proof-of-concept exploit has been disclosed.

Affected products

  • code-projects Easy Blog Site 1.0

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References

Related threats