CVE-2026-13011 | wedevs ERP: Complete HR, Accounting & CRM Suite Plugin up to 1.17.5 Query orderby sql injection

SecurityVulns

A vulnerability categorized as critical has been discovered in wedevs ERP: Complete HR, Accounting & CRM Suite Plugin up to 1.17.5. Impacted is an unknown function of the component Query Handler. Executing a manipulation of the argument orderby can lead to sql injection.

This vulnerability is registered as CVE-2026-13011. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More