Vendor
high
threat
SQL Injection in FilePress Publish Module
1 TTP 1 CVEAn unpatched SQL injection vulnerability in zyx0814 FilePress versions 3.0.1 and earlier allows remote attackers to manipulate the orderby or order arguments within search.php.
exploited
FilePress
sqli
web-vulnerability
1t
1c
high
advisory
zyx0814 FilePress SQL Injection Vulnerability (CVE-2026-8133)
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-8133) exists in zyx0814 FilePress up to version 2.2.0 via the Shares Filelist API by manipulating the argument order, potentially leading to unauthorized data access or modification.
FilePress
sql-injection
vulnerability
web-application
2r
1t
1c