Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-12582— Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id

AI Predicted 9.8 Difficulty: Easy EPSS 0.26% · P18

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProductVersion RangeStatus
UnknownLibrary Management System3.5< 3.5.8affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-12582

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id
Source: CVE Program / CVE List V5
Vulnerability Description
The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user password hashes.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress Library Management System SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Online Web Tutor Library Management System是Online Web Tutor团队的一款图书馆管理软件。 WordPress Library Management System 3.5.8之前版本存在SQL注入漏洞,该漏洞源于未清理和转义用户提供的参数,允许未经身份验证的攻击者进行SQL注入并从数据库中提取任意数据,包括用户密码哈希。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
UnknownLibrary Management System 3.5 ~ 3.5.8 -

II. Public POCs for CVE-2026-12582

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12582

登录查看更多情报信息。

Vendor Advisories for CVE-2026-12582 (1)

Same Patch Batch · Unknown · 2026-07-13 · 11 CVEs total

CVE-2026-12275Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content
CVE-2026-12397WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR
CVE-2026-12396WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rejection
CVE-2026-11964User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verifica
CVE-2026-12081Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object
CVE-2026-12273Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation
CVE-2026-12271Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR
CVE-2026-12274Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR
CVE-2026-11963User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier M
CVE-2026-10551Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library

IV. Related Vulnerabilities

V. Comments for CVE-2026-12582

No comments yet


Leave a comment