🔐 CVE Alert

CVE-2026-81672

UNKNOWN 0.0

Multiple Vulnerabilities in TOOOLS' iSquad

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The vulnerability exposes internal file paths and complete stack traces through the Slim framework’s error handler, which increases the severity due to the combination of information disclosure and SQL injection.

CWE CWE-89
Vendor toools
Product isquad
Published Aug 27, 2026
Last Updated Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for toools isquad

Be the first to know when new unknown vulnerabilities affecting toools isquad are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

TOOOLS / iSquad
0 < 22/07/2026

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-toools-isquad

Credits

DylanCV