Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6490

25
FAUCET Score

CVE-2026-6490 is a SQL injection vulnerability affecting QueryMine SMS up to commit 7ab5a9ea196209611134525ffc18de25c57d9593, specifically within the admin/deletecourse.php file's GET request parameter handler. The flaw exists in the ID parameter, which fails to properly sanitize user input before database queries. Due to QueryMine's rolling release model, specific affected version numbers are not available, complicating patch identification for end users. The vulnerability carries a HIGH severity rating of 7.3 on the CVSS scale and can be exploited remotely without authentication or user interaction required. Attack complexity is low, meaning exploitation does not require specialized conditions or techniques. The compromise could result in unauthorized data access, data modification, and potential service disruption, affecting the confidentiality, integrity, and availability of the application. Public exploit code has been released, significantly increasing the risk of active exploitation in the wild. The vulnerability is currently listed on security hotlists and requires immediate attention despite the low EPSS score. The vendor has been notified but did not respond, leaving organizations dependent on self-remediation or community-provided patches until an official update is released.

Impacted Technologies

VendorProductVersion(s)CPE
QueryMineSms
7ab5a9ea196209611134525ffc18de25c57d9593CNA affected

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.33%
Probability of exploitation in next 30 days
EPSS Percentile
24.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 7th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / duckpigdog/CVE/blob/main/QueryMine_sms%20PHP%20Project%20Deployment%20Document%20(Windows%20Local)-1.md
vuldb.com / submit/786912
vuldb.com / vuln/358034
vuldb.com / vuln/358034/cti