CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-34100 — Critical vulnerability brief

July 1, 2026CVSS 9.3

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '".$_GET['id']."'. An authenticated attacker can perform error-based SQL injection to extract database contents.

CVSS base score: 9.3 / 10

View NVD record