Ismalicious SQL Injection Vulnerabilities Discovered in Hotel and Tourism Reservation Software
Article Content
- •Two high-severity SQL injection vulnerabilities found in Hotel and Tourism Reservation 1.0.
- •CVE-2026-14755 and CVE-2026-14756 allow remote exploitation via specific arguments.
- •Active exploitation has not been confirmed, but users should remain vigilant.
Two vulnerabilities, CVE-2026-14755 and CVE-2026-14756, have been identified in the Hotel and Tourism Reservation 1.0 software. CVE-2026-14755 affects the /admin/reservations.php file, while CVE-2026-14756 impacts the /admin/add_tour.php file. Both vulnerabilities allow for SQL injection through the manipulation of specific arguments, which can be exploited remotely. The CVSS score for both vulnerabilities is 7.3, indicating high severity. Active exploitation has not been confirmed for either CVE, and the EPSS scores are not available. The vulnerabilities were disclosed to the public on July 5, 2026. Users of the affected software are advised to monitor for potential exploitation. No specific patches or mitigation strategies have been provided yet.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-14755 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…