CVE-2026-81672
Multiple Vulnerabilities in TOOOLS' iSquad
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The vulnerability exposes internal file paths and complete stack traces through the Slim framework’s error handler, which increases the severity due to the combination of information disclosure and SQL injection.
| CWE | CWE-89 |
| Vendor | toools |
| Product | isquad |
| Published | Aug 27, 2026 |
| Last Updated | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for toools isquad
Be the first to know when new unknown vulnerabilities affecting toools isquad are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TOOOLS / iSquad
0 < 22/07/2026
References
Credits
DylanCV