Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php. An attacker can perform error-based SQL injection to extract database contents.
An authenticated attacker over the network can extract sensitive data from the database and modify or delete database contents through SQL injection.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Yes, a patch is available at
Apply the available patch immediately. Additionally, implement input validation and parameterized queries to prevent SQL injection, ensure the principle of least privilege for database accounts, and monitor for suspicious SQL query patterns in logs.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
NVD published the first details for CVE-2026-34103
A CVSS base score of 9.8 has been assigned.
Feedly found the first article mentioning CVE-2026-34103 . See article
GitHub Advisories released a security advisory .
[GHSA-94h9-6mg7-9wvx] Guardian language-system passes the id GET parameter directly into an unsanitize
CVE-2026-34103 - Guardian Language-System Unauthenticated SQL Injection via id Parameter in subtitles.php CVE ID : CVE-2026-34103 Published : July 1, 2026, 4:12 p.m. | 1 hour ago Description : Guardian language-system passes the id GET parameter directly into an unsaniti...
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
