CVE-2026-18737 | shlinkio Shlink up to 5.1.5 Tag Statistics Endpoint orderBy sql injection (EUVD-2026-52434)
A vulnerability was found in shlinkio Shlink up to 5.1.5. It has been declared as critical. This issue affects some unknown processing of the component Tag Statistics Endpoint. Such manipulation of the argument orderBy leads to sql injection.
This vulnerability is traded as CVE-2026-18737. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More