CVE-2026-1105 | EasyCMS up to 1.6 /UserAction.class.php _order sql injection (EUVD-2026-3192 / CNNVD-202601-2970)
A vulnerability described as critical has been identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of the argument _order leads to sql injection.
This vulnerability is documented as CVE-2026-1105. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.