CVE-2026-13011 | wedevs ERP: Complete HR, Accounting & CRM Suite Plugin up to 1.17.5 Query orderby sql injection
A vulnerability categorized as critical has been discovered in wedevs ERP: Complete HR, Accounting & CRM Suite Plugin up to 1.17.5. Impacted is an unknown function of the component Query Handler. Executing a manipulation of the argument orderby can lead to sql injection.
This vulnerability is registered as CVE-2026-13011. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More