CVE-2026-14743: Code-Projects Real State Services

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was identified in code-projects Real State Services 1.0. The impacted element is an unknown function of the file /normalHomeSale.php. Such manipulation of the argument loc leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

Affected products

Published 2026-07-05. Last modified 2026-07-06.