Projectworlds Vulnerabilities
Comprehensive security vulnerability database for Projectworlds products
4
0
4
3
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2026-3759 | 6.9 | This vulnerability allows an attacker to remotely manipulate the online art gallery shop's database by injecting malicious SQL code through a specific part of the admin interface. To exploit this, the attacker needs access to the adminHome.php file and can target it without needing any special permissions. | projectworldsonline art gallery shop | Exploit Available | 30 days agoMar 8, 2026 |
| CVE-2026-3758 | 6.9 | This vulnerability allows an attacker to manipulate a specific part of the online art gallery's admin panel to execute unauthorized database commands, potentially exposing sensitive information. The attacker can exploit this weakness remotely, meaning they don't need physical access to the system, and the method to do so is publicly available. | projectworldsonline art gallery shop | Exploit Available | 30 days agoMar 8, 2026 |
| CVE-2026-3757 | 6.9 | This vulnerability allows an attacker to remotely manipulate the online art gallery shop's database by injecting malicious SQL commands through a specific URL parameter. To exploit this flaw, the attacker needs to know how to craft the right request, which could lead to unauthorized access to sensitive data or even complete control over the database. | projectworldsonline art gallery shop | Exploit Available | 30 days agoMar 8, 2026 |
| CVE-2026-3406 | 6.9 | An attacker can remotely manipulate the registration process of the online art gallery shop to execute malicious SQL commands, potentially gaining access to sensitive data in the database. This vulnerability occurs when the attacker alters a specific input field, making it crucial for the site administrators to patch this issue promptly. | projectworldsonline art gallery shop | Exploit Available | about 1 month agoMar 2, 2026 |
About Projectworlds Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Projectworlds products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.