Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection.

This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-06
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of special elements in an SQL command allows a malicious actor to inject arbitrary SQL into the Loca Software CMS. This SQL injection flaw (CWE-89) can lead to unauthorized data exposure, modification, or deletion, and may enable further compromise of the underlying database. The vulnerability is documented as a high-severity threat with a CVSS score of 9.8.

Affected Systems

The vulnerability affects the Loca Software Informatics Technology Ltd. Co. CMS, versions through 06082026. No specific sub-versions are listed; any deployment of that CMS prior to a patch is considered vulnerable.

Risk and Exploitability

The CVSS score indicates a critical impact. Because the EPSS score is not available and the flaw is not yet listed in the CISA KEV catalog, the current exploitation probability is unknown, but the high severity suggests a strong likelihood of exploitation. The attack vector is inferred to be remote via the web interface, as the CMS processes external input in SQL statements. Attackers could exploit this without prior authentication if input validation is lacking.

Generated by OpenCVE AI on August 6, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify your CMS version and confirm whether it is susceptible to this flaw.
  • Monitor the vendor’s website for an official patch; apply the patch immediately once released.
  • Until a patch is available, enforce strict input validation or use parameterized queries to eliminate unsanitized SQL injection.
  • Deploy a web application firewall to detect and block known SQL injection payloads.
  • Restrict database credentials and monitor database activity for anomalous queries.

Generated by OpenCVE AI on August 6, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Critical


Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Loca Software Informatics Technology
Loca Software Informatics Technology cms
Vendors & Products Loca Software Informatics Technology
Loca Software Informatics Technology cms

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title SQLi in Loca Software's CMS
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Loca Software Informatics Technology Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-06T14:42:41.239Z

Reserved: 2026-03-30T10:11:27.574Z

Link: CVE-2026-5134

cve-icon Vulnrichment

Updated: 2026-08-06T14:42:38.317Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T14:16:36.840

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-5134

cve-icon Redhat

Severity : Critical

Publid Date: 2026-08-06T13:31:45Z

Links: CVE-2026-5134 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:00:45Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')