Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2026-34106

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in subtitles.php_CVE-2026-34106

Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jo...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34105

Guardian Language-System Unauthenticated SQL Injection via id Parameter in translate_text.php_CVE-2026-34105

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, e...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34104

Guardian Language-System Unauthenticated SQL Injection via name Parameter in designer.php_CVE-2026-34104

Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHE...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34103

Guardian Language-System Unauthenticated SQL Injection via id Parameter in subtitles.php_CVE-2026-34103

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extens...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34102

Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info_get.php_CVE-2026-34102

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34101

Guardian Language-System Unauthenticated SQL Injection via id Parameter in text_file.php_CVE-2026-34101

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extens...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34100

Guardian Language-System Unauthenticated SQL Injection via id Parameter in media.php_CVE-2026-34100

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension,...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34099

Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info.php_CVE-2026-34099

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id ...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34117

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text_to_subtitles.php_CVE-2026-34117

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) without sanitization: exec(...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34116

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe.php_CVE-2026-34116

Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php j...

guardian language-system CVE