CVE-2026-108100

CVE-2026-108100 published: HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which Plan...

View full NVD advisory → ← Back to CVE watch