AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-5134

CRITICAL · CVSS 9.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A critical SQL injection vulnerability exists in Loca Software Informatics Technology Ltd. Co. CMS, allowing attackers to manipulate SQL queries and potentially gain unauthorized access to sensitive data. Organizations using this CMS should prioritize immediate remediation efforts, as the lack of vendor response raises concerns about timely patches and support.

CVE
CVE-2026-5134
Severity
CRITICAL
CVSS
9.8
EPSS
0.27%

Original NVD Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.