CVE-2026-9163
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-89
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- GIS Informatics GisLab Laboratory Management System
Weakness type
Related vulnerabilities
- CVE-2026-89089 — OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parameter (ROLE_USER)
- CVE-2026-73698 — FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action
- CVE-2026-81800 — WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability
- CVE-2026-88890 — OpenPanel SQL Injection via unvalidated profile filter column identifier
- CVE-2026-78082 — Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4
- CVE-2026-7188 — SQLi in Armiya Information Technologies' Access Control System
- CVE-2026-87925 — Rizwan17 inventory-management-system manage.php storeCustomerOrderInvoice sql injection
- CVE-2026-87921 — Rizwan17 inventory-management-system manage.php update_record sql injection