OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-108100 (CVSS 7.1)

NVD · officialPublished Oct 9, 2026Risk 23/100

HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.

CVSS
7.1
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source