CRITICAL 9.0 CVE-2026-68954 Published 29 Sept 2026

TMS Application Home Page Search SQL Injection Vulnerability

Worried this affects your website?

The TMS application is vulnerable to a time-based blind SQL injection flaw in the search function on its home page.

The vulnerability is triggered through the pattern parameter, allowing an attacker to exploit the search feature to perform time-based blind SQL injection.

Reference: CVE-2026-68954 on NVD

← Back to Security News