Skip to content
CVE-2026-34105 - Exploits & Severity

CVE-2026-34105 - Exploits & Severity

Feedly • July 2, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

Guardian language-system fails to sanitize the id GET parameter before inserting it into a SQL query in translate_text.php, allowing SQL injection attacks. An authenticated attacker can exploit this via error-based SQL injection to extract sensitive information from the database.

An authenticated attacker over the network can perform SQL injection to extract arbitrary data from the database, modify database contents, or potentially execute commands depending on database permissions.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Update Guardian language-system to the patched version. Additionally, implement parameterized queries or prepared statements to prevent SQL injection, validate and sanitize all user inputs before use in SQL queries, and implement principle of least privilege for database accounts used by the application.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

NVD published the first details for CVE-2026-34105

Feedly found the first article mentioning CVE-2026-34105 . See article

GitHub Advisories released a security advisory .

CVE-2026-34105 - Exploits & Severity - Feedly

CVE-2026-34105 - Guardian Language-System Unauthenticated SQL Injection via id Parameter in translate_text.php CVE ID : CVE-2026-34105 Published : July 1, 2026, 4:15 p.m. | 57 minutes ago Description : Guardian language-system passes the id GET parameter directly into an...

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)