CVE-2026-10262
📛 CVE Title
code-projects Real State Services Login loginuser.php sql injection
Description
A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- VulDB
- CVSS severity
- MEDIUM
- CVSS score
- 6.9 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P- Effective score
- 6.9 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-89,CWE-74 - Reserved
- 2026-05-31
- Published
- 2026-06-01 13:45 UTC
- Last updated
- 2026-06-01 18:31 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/10xxx/CVE-2026-10262.json
- Linked Threat
- CVE-2026-10262 — CVE-2026-10262
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-06-01 15:16:32 UTC
- NVD last modified
- 2026-07-22 07:10:00 UTC
- NVD CVSS v3.1
- 7.3 / 10 HIGH source: cna@vuldb.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 3.4 / 10
- EPSS score
- 0.0027 (probability of exploitation in next 30 days)
- EPSS percentile
- 18.80% vs all CVEs — higher = more likely to be exploited, as of 2026-07-27
NVD / KEV / EPSS data refreshed 2026-07-27 20:38 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-33644 - Assigner
- VulDB
- Published
- Jun 1, 2026, 1:45:08 PM
- Updated
- Jun 1, 2026, 6:31:38 PM
- EUVD base score (CVSS 4.0)
-
6.9 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P - EUVD-reported EPSS
- 0.2700
- Vendors
- code-projects
- Products
-
Real State Services (1.0)
- Aliases
-
GHSA-2h9g-8p3q-w23q
ENISA description: A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| code-projects | Real State Services |
1.0 (affected)
|
— |
Vendor references (6)
References embedded in the original CVE record by the assigning CNA.
- VDB-367542 | code-projects Real State Services Login loginuser.php sql injection vdb-entrytechnical-description
- VDB-367542 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-required
- CVE-2026-10262 | CVE Analysis and Report third-party-advisory
- Submit #824877 | code-projects Real State Services V1.0 SQL Injection third-party-advisory
- https://github.com/6Justdododo6/CVE/issues/20 exploitissue-tracking
- https://code-projects.org/ product
Web references (9)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://code-projects.org/ tenable:code-projects.org
- https://github.com/6Justdododo6/CVE/issues/20 tenable:github.com
- https://nvd.nist.gov/vuln/detail/CVE-2026-10262 tenable:nvd.nist.gov
- https://vuldb.com/cve/CVE-2026-10262 tenable:vuldb.com
- https://vuldb.com/submit/824877 tenable:vuldb.com
- https://vuldb.com/vuln/367542 tenable:vuldb.com
- https://vuldb.com/vuln/367542/cti tenable:vuldb.com
- https://www.cve.org/CVERecord?id=CVE-2026-10262 tenable:www.cve.org
- https://www.first.org/epss/ tenable:www.first.org
NVD-tagged references (6)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://code-projects.org/ cna@vuldb.com
- https://github.com/6Justdododo6/CVE/issues/20 cna@vuldb.com
- https://vuldb.com/cve/CVE-2026-10262 cna@vuldb.com
- https://vuldb.com/submit/824877 cna@vuldb.com
- https://vuldb.com/vuln/367542 cna@vuldb.com
- https://vuldb.com/vuln/367542/cti cna@vuldb.com
Remediations (20)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:blog.qualys.com
May 2026's Patch Tuesday arrives with Microsoft addressing a fresh set of vulnerabilities across its ecosystem, reinforcing the ongoing need for timely patching in an increasingly threat-heavy…
2026-06-08 15:58 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-06-08 15:58 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-06-08 15:58 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-08 15:58 UTC -
web:security.paloaltonetworks.com
Palo Alto Networks Security Advisory: CVE - 2026 -0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to a dataplane interface. Panorama, Cloud NGFW ...
2026-06-08 15:58 UTC -
web:securityboulevard.com
Organizations must decide how to tackle vulnerabilities—through remediation , mitigation , or a combination of both. But which strategy is more effective? This blog explores the nuances of vulnerability remediation vs mitigation , their respective benefits, and how to choose the right approach.
2026-06-08 15:58 UTC -
web:support.microsoft.com
Summary Improvements and fixes included in this update How to obtain and install the update More information File information Information about protection and security Summary This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories: CVE - 2026 -21262 - SQL Server Elevation of Privilege Vulnerability CVE-2026 ...
2026-06-08 15:58 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-06-08 15:58 UTC -
web:www.secure.com
Remediation fully removes a vulnerability by fixing its root cause — through a patch , code fix , or system replacement. Mitigation reduces the risk of exploitation without removing the flaw itself, using controls like network segmentation or access restrictions.
2026-06-08 15:58 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-06-08 15:58 UTC -
web:cybersecuritytimes.com
Microsoft released its March 2026 Patch Tuesday security update on March 10, 2026 , addressing 79 vulnerabilities across Windows, Microsoft Office, Azure services, SQL Server, .NET, and other core components.
2026-06-19 02:31 UTC -
web:gbhackers.com
Microsoft has released its March 2026 Patch Tuesday updates, successfully addressing 79 security vulnerabilities across various products and mitigating two publicly disclosed zero-day flaws. These critical security updates provide essential fixes for enterprise systems, including Microsoft Windows, Office, SQL Server, and the .NET framework.
2026-06-19 02:31 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-06-19 02:31 UTC -
web:patch.com
Buffalo Grove Latest Headlines: $10.5M Settlement Reached In Fatal Elk Grove Police Shooting; Buffalo Grove Residents Earn Degrees From Carthage College ; 4 Simple Money Hacks Anyone Can Try
2026-06-19 02:31 UTC -
web:techcommunity.microsoft.com
UPDATE June 9, 2026 : Please see our release blog post for June 2026 Security Update for more information on this CVE : Released: June 2026 Exchange Server Security Updates | Microsoft Community Hub. On May 14, 2026 , Microsoft disclosed CVE - 2026 -42897, a reported vulnerability affecting Exchange Outlook Web Access (OWA). An attacker could exploit this issue by sending a specially crafted email ...
2026-06-19 02:31 UTC -
web:threatprotect.qualys.com
Zero-day Vulnerabilities Patched in April Patch Tuesday Edition CVE - 2026 -33825: Microsoft Defender Elevation of Privilege Vulnerability Microsoft Defender is a comprehensive, AI-powered security suite that provides malware protection, phishing detection, and web protection for individuals and businesses.
2026-06-19 02:31 UTC -
web:vulners.com
A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initia...
2026-06-19 02:31 UTC -
web:www.cisa.gov
BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV catalog vulnerabilities.
2026-06-19 02:31 UTC -
web:www.sherlockforensics.com
CVE-2026-10262 is a high severity vulnerability (CVSS 7.3) identified in the National Vulnerability Database. A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been ...
2026-06-19 02:31 UTC -
web:www.thehackerwire.com
CVE-2026-10262 is a High severity vulnerability (CVSS 7.3). A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php...
2026-06-19 02:31 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-10262.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-10262",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-01T18:29:58.139122Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-01T18:31:38.947Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:code-projects:real_state_services:*:*:*:*:*:*:*:*"
],
"modules": [
"Login"
],
"product": "Real State Services",
"vendor": "code-projects",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "XuYue (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "SQL Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-01T13:45:08.184Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-367542 | code-projects Real State Services Login loginuser.php sql injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/367542"
},
{
"name": "VDB-367542 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/367542/cti"
},
{
"name": "CVE-2026-10262 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-10262"
},
{
"name": "Submit #824877 | code-projects Real State Services V1.0 SQL Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/824877"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/6Justdododo6/CVE/issues/20"
},
{
"tags": [
"product"
],
"url": "https://code-projects.org/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-05-31T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-05-31T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-05-31T14:53:17.000Z",
"value": "VulDB entry last update"
}
],
"title": "code-projects Real State Services Login loginuser.php sql injection"
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-10262",
"datePublished": "2026-06-01T13:45:08.184Z",
"dateReserved": "2026-05-31T12:48:14.352Z",
"dateUpdated": "2026-06-01T18:31:38.947Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}