CVE-2026-38626

Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.

  • Published Sep 10, 2026
  • CVSS 9.8 critical
  • 0.5% chance of exploitation in the next 30 days (EPSS)

CVE-2026-38626 at the National Vulnerability Database