CVE-2026-5565 is a SQL injection vulnerability in Simple Laundry System version 1.0, specifically in the /delmemberinfo.php file's userid parameter handler. The vulnerability allows attackers to manipulate this parameter to execute arbitrary SQL commands against the application's database. The vulnerability carries a CVSS score of 7.3 (HIGH), with a network-based attack vector requiring no authentication, low complexity, and no user interaction. The impact is moderate, affecting confidentiality, integrity, and availability through potential data exposure, modification, or system disruption. Exploitation appears limited at present. While proof-of-concept exploit code has been publicly disclosed, the vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no indication of active exploitation in the wild. The EPSS score of 0.000390 suggests low probability of exploitation within the next 30 days, and it remains inactive on the Hot List, indicating minimal community attention or real-world abuse at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Code-Projects | Simple Laundry System | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.