Description
A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection allowing unauthorized database access
Action: Monitor
AI Analysis

Impact

This flaw in the FilePress Publish module permits an attacker to alter the orderby and order query parameters in dzz/publish/search.php, resulting in arbitrary SQL injection. The injection can disclose confidential data, modify database records, or perform destructive database operations, thereby compromising the confidentiality and integrity of the application’s data. The vulnerability is exploitable remotely and a public exploit is available, meaning it can be leveraged without any special access.

Affected Systems

The affected product is FilePress by zyx0814. Versions up to and including 3.0.1 are vulnerable. The flaw resides in the Publish module’s dzz/publish/search.php file. No specific later versions are known to be unaffected until a patch is released.

Risk and Exploitability

The CVSS base score of 6.9 indicates medium severity while the EPSS score of < 1% suggests a low yet non‑zero likelihood of exploitation. Because the attack is remote and a public exploit exists, the risk remains real. The vulnerability is not yet catalogued in the CISA KEV list.

Generated by OpenCVE AI on September 17, 2026 at 19:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and apply any security update or patch released by zyx0814 that fixes the SQL injection flaw in the Publish module.
  • If no patch is available, restrict access to the dzz/publish/search.php endpoint by configuring the web server or application firewall to allow only trusted IP addresses, or disable the Publish module entirely.
  • Implement input validation that whitelists acceptable values for the orderby and order parameters and use parameterized queries or proper escaping in the database access code to prevent injection.

Generated by OpenCVE AI on September 17, 2026 at 19:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Title zyx0814 FilePress Publish search.php sql injection
First Time appeared Zyx0814
Zyx0814 filepress
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:zyx0814:filepress:*:*:*:*:*:*:*:*
Vendors & Products Zyx0814
Zyx0814 filepress
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Zyx0814 Filepress
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:00:15.630Z

Reserved: 2026-09-14T07:16:18.433Z

Link: CVE-2026-90879

cve-icon Vulnrichment

Updated: 2026-09-15T14:00:07.542Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T05:17:00.537

Modified: 2026-09-15T15:17:30.850

Link: CVE-2026-90879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')