CVE-2026-9364: projectworlds Online Art Gallery Shop adminHome.php sql injection
Published May 24, 2026
·Updated
A flaw has been found in projectworlds Online Art Gallery Shop 1.0. Impacted is an unknown function of the file /admin/adminHome.php. Executing a manipulation of the argument social_linked can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
1 affected component
Projectworlds Online Art Gallery Shop=1.0
Event History
May 24, 2026
CVE Published
via MITRE·07:30 AM
Data Sourced
via MITRE·07:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-9364?
The severity of CVE-2026-9364 is rated high with a score of 7.3.
2
How do I fix CVE-2026-9364?
To fix CVE-2026-9364, you should sanitize and validate all input parameters, particularly the 'social_linked' argument, to prevent SQL injection.
3
What type of vulnerability is CVE-2026-9364?
CVE-2026-9364 is classified as an SQL injection vulnerability.
4
Can CVE-2026-9364 be exploited remotely?
Yes, CVE-2026-9364 can be exploited remotely due to its nature of SQL injection.
5
What software is affected by CVE-2026-9364?
CVE-2026-9364 affects Projectworlds Online Art Gallery Shop version 1.0.