CVE-2026-19425: Win Men Intermational Travel Agency Management System

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.

Affected products

Published 2026-08-11. Last modified 2026-08-26.