CVE-2026-108100: Danielbrendel Hortusfox-Web
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.
Affected products
- Danielbrendel Hortusfox-Web: before 6.2 (fixed in 6.2)
Published 2026-10-09. Last modified 2026-10-09.