Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

itsourcecode News Portal Project 1.0 SQL Injection via Admin Panel

CVE-2026-3135
Summary

A security weakness in the itsourcecode News Portal Project 1.0 allows hackers to manipulate data in the admin panel, putting sensitive information at risk. This could happen if an attacker sends malicious input to the system through the admin panel. To stay safe, the software should be updated with a fix or patch as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
clive_21 news_portal_project 1.0 –
Original title
A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.php. This manipulation of the argument Category c...
Original description
A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
nvd CVSS2.0 7.5
nvd CVSS3.1 9.8
nvd CVSS4.0 6.9
Vulnerability type
CWE-74 Injection
CWE-89 SQL Injection
Published: 25 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026