Mmastodon TechnologyCybersecurity first seen 1 d ago, last 1 d ago, peak #11
HortusFox patches SQL injection flaw in versions before 6.2
Original: π¨ EUVD-2026-95791 π Score: 7.1/10 (CVSS v3.1) π¦ Product: hortusfox-web π’ Vendor: danielbrendel π Updated: 2026-10-09 π H
A medium-severity SQL injection vulnerability, tracked as EUVD-2026-95791 with a CVSS score of 7.1, has been disclosed in HortusFox (hortusfox-web), the self-hosted plant management application by developer danielbrendel. Versions before 6.2 allow API token holders to inject SQL through a crafted include_info parameter. Users are advised to update to 6.2 or later.
Why now: Self-hosted application users and security watchers are being alerted to the newly disclosed vulnerability and the available fix.
HortusFoxdanielbrendelEUVD-2026-95791
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1627862