Security Digest: July 5, 2026 - 14 Critical Vulnerabilities

Today’s advisory set is dominated by publicly disclosed, remotely exploitable flaws across multiple small-business and open-source web applications, with a heavy concentration of SQL injection and authorization bypass issues. Several affected products expose login, registration, and admin endpoints, which means attackers may be able to steal data, create accounts, bypass access controls, or pivot into deeper compromise if these systems are internet-facing.

· 12 min read

Urgent Security Digest: 14 High-Risk Vulnerabilities Demand Immediate Action

Executive Summary

Today’s advisory set is dominated by publicly disclosed, remotely exploitable flaws across multiple small-business and open-source web applications, with a heavy concentration of SQL injection and authorization bypass issues. Several affected products expose login, registration, and admin endpoints, which means attackers may be able to steal data, create accounts, bypass access controls, or pivot into deeper compromise if these systems are internet-facing.

Action required now: identify whether you run any of the affected products, remove exposure where possible, and apply vendor fixes or disable vulnerable endpoints immediately. Because exploit code is already public for most of these issues, waiting for routine maintenance windows is not a safe option.

Critical Vulnerabilities

CVE-2026-14688: SQL injection in itsourcecode Online Hotel Management System 1.0 login

Impact: Remote attackers may inject SQL through the admin login email field, risking account takeover and database exposure.

Affected Systems: itsourcecode Online Hotel Management System 1.0, /admin/login.php

Immediate Action: Take the admin portal offline or restrict it to trusted IPs now; inspect logs for suspicious login attempts.

Mitigation: Apply a vendor fix if available, replace dynamic SQL with parameterized queries, and rotate credentials used by the admin interface.

CVE-2026-14690: Improper authorization in SourceCodester Multi-Vendor Online Grocery Management System 1.0

Impact: Attackers may bypass intended access controls and perform privileged actions remotely.

Affected Systems: SourceCodester Multi-Vendor Online Grocery Management System 1.0, classes/Users.php (save_users)

Immediate Action: Disable user-management functions until patched and review whether unauthorized accounts or role changes have occurred.

Mitigation: Update to a fixed release, enforce server-side authorization checks, and audit all user creation and role assignment events.

CVE-2026-14695: SQL injection in grocery system registration handler

Impact: Remote attackers can manipulate the Name field to inject SQL, potentially exposing or altering customer data.

Affected Systems: SourceCodester Multi-Vendor Online Grocery Management System 1.0, classes/Users.php (save_client)

Immediate Action: Temporarily disable public registration and block direct access to the registration endpoint.

Mitigation: Patch immediately, validate and parameterize input handling, and review the database for signs of tampering.

CVE-2026-14700: SQL injection in Internship Management System employer login

Impact: Attackers can exploit the login form to bypass authentication or extract sensitive records.

Affected Systems: code-projects Internship Management System 1.0, employer/login.php

Immediate Action: Restrict employer login access and monitor authentication logs for malformed requests.

Mitigation: Patch the application, use prepared statements, and reset any credentials that may have been exposed.

CVE-2026-14705: SQL injection in Online Examination 1.0 head.php

Impact: Remote attackers may bypass authentication or access exam data and user records.

Affected Systems: code-projects Online Examination 1.0, head.php

Immediate Action: Remove the system from public exposure if possible and block suspicious login traffic at the edge.

Mitigation: Apply the vendor update, harden login handling, and verify the integrity of exam and user tables.

CVE-2026-14713: SQL injection in Pizzafy E-Commerce order confirmation

Impact: Attackers can manipulate order confirmation requests to access or alter backend data.

Affected Systems: SourceCodester Pizzafy E-Commerce System 1.0, /admin/ajax.php?action=confirm_order

Immediate Action: Lock down admin AJAX endpoints and review order processing for unauthorized changes.

Mitigation: Patch immediately, validate all order IDs server-side, and replace unsafe query construction.

CVE-2026-14719: Improper privilege management in online examination and learning platform

Impact: Remote attackers may assign themselves elevated roles during registration.

Affected Systems: SourceCodester Onlne Examination & Learning Management System 1.0, register.php

Immediate Action: Suspend self-service registration and verify that no unauthorized privileged accounts exist.

Mitigation: Patch the application, enforce role assignment only on the server side, and review all new accounts created since exposure.

CVE-2026-14722: Code injection in TidGi-Desktop Git repository import

Impact: A malicious or crafted repository may trigger code execution during import.

Affected Systems: tiddly-gittly TidGi-Desktop up to 0.13.0, src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts

Immediate Action: Stop importing untrusted repositories and upgrade affected desktop clients immediately.

Mitigation: Update to a fixed version, restrict repository sources, and review any imported content from untrusted origins.

CVE-2026-14732: SQL injection in Class and Exam Timetabling System edit_exam

Impact: Remote attackers may alter exam records or extract database contents.

Affected Systems: SourceCodester Class and Exam Timetabling System 1.0, /edit_exam.php

Immediate Action: Block access to the edit endpoints and check for unauthorized schedule changes.

Mitigation: Patch the system, parameterize the ID field, and validate database integrity.

CVE-2026-14733: SQL injection in Class and Exam Timetabling System edit_coursea

Impact: Attackers can manipulate course data and potentially compromise the backend database.

Affected Systems: SourceCodester Class and Exam Timetabling System 1.0, /edit_coursea.php

Immediate Action: Restrict access to course-editing functions and monitor for suspicious parameter values.

Mitigation: Apply fixes, sanitize all request parameters, and audit recent course modifications.

CVE-2026-14734: SQL injection in Class and Exam Timetabling System edit_product

Impact: Remote attackers may tamper with product records or access sensitive data.

Affected Systems: SourceCodester Class and Exam Timetabling System 1.0, /edit_product.php

Immediate Action: Disable the affected page and review logs for repeated ID-based requests.

Mitigation: Patch immediately, use prepared statements, and verify that no records were altered unexpectedly.

CVE-2026-14735: SQL injection in Smart Parking System parking management

Impact: Attackers may manipulate parking records, user data, or backend database content.

Affected Systems: code-projects Smart Parking System 1.0, /parkings/parkings.php

Immediate Action: Restrict access to the parking admin interface and inspect for abnormal request patterns.

Mitigation: Patch the application, validate the street, city, and status fields server-side, and rotate database credentials if exposure is suspected.

CVE-2026-14736: Unrestricted file upload in Ruijie RG-UAC

Impact: Remote attackers may upload malicious files, which can lead to code execution or device compromise.

Affected Systems: Ruijie RG-UAC up to 1.0-R1.8.2.p5, user_auth_commit.php

Immediate Action: Isolate management access, block file upload functionality if possible, and treat the device as high priority.

Mitigation: Apply the vendor update, enforce strict upload restrictions, and review the device for suspicious files or new admin activity.

CVE-2026-14737: SQL injection in Hanwang e-Face General Management Platform

Impact: Remote attackers may access or modify authentication-related data and other sensitive records.

Affected Systems: Hanwang e-Face General Management Platform 6.3.5.4, /sysAuthStr/querySysAuthStr.do

Immediate Action: Restrict exposure of the management platform and review all authentication queries for abuse.

Mitigation: Patch immediately, parameterize the order input, and audit account and permission changes.

What to Do Now

  1. Inventory exposure now. Identify whether any of these products are internet-facing, especially admin, login, registration, and AJAX endpoints.
  2. Contain first, patch second. If no patch is available yet, restrict access by IP allowlist, VPN, firewall rules, or temporary shutdown.
  3. Prioritize public exploit risk. Assume active scanning is already underway because exploit code is publicly available for most issues listed here.
  4. Check for compromise. Review authentication logs, database activity, new accounts, role changes, and unexpected file uploads.
  5. Rotate secrets if exposure is suspected. Reset admin passwords, database credentials, API keys, and session secrets where applicable.

Verification steps: confirm installed versions, compare against affected releases, and validate whether vulnerable endpoints are still reachable from the internet. Run targeted searches for the affected file paths and parameters listed above, then inspect logs for repeated ID, email, role, uname, password, and upload_image payloads.

Monitoring recommendations: alert on spikes in 4xx/5xx responses, unusual POST activity to admin endpoints, new file uploads, and unexpected database writes. For exposed web apps, increase WAF logging and watch for automated probing from known scanning infrastructure.

Related Resources

  • Internal: upcoming blog post on emergency hardening for public-facing PHP applications.
  • Internal: upcoming blog post on detecting SQL injection and unauthorized file upload abuse.
  • Official vendor advisories: monitor vendor security pages for SourceCodester-derived products, code-projects releases, Ruijie security notices, Hanwang advisories, and TidGi-Desktop release notes.

Keep reading