AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19425

CRITICAL · CVSS 9.8 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Travel Agency Management System by Win Men International is vulnerable to a critical SQL Injection flaw, allowing unauthenticated remote attackers to execute arbitrary SQL commands. This could lead to unauthorized access, modification, or deletion of sensitive database information. Organizations utilizing this system should prioritize immediate remediation to mitigate potential data breaches and integrity loss.

CVE
CVE-2026-19425
Severity
CRITICAL
CVSS
9.8
EPSS
0.47%

Original NVD Description

Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.