AllCyberNews

CVE-2026-68954

Toptech TMS7 and TopHAT SQL Injection

CVSS 8.5 high · Toptech Systems TMS7 · published 2026-09-29

The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.

Coverage 1 source

  1. 2026-09-29 CISA Cybersecurity Advisories high Toptech TMS7 and TopHAT

    Multiple vulnerabilities affect Toptech TMS7 and TopHAT versions 7.6.3.

Mentioned with

CVE-2026-63713 CVE-2026-68068 CVE-2026-69662 CVE-2026-70356 CVE-2026-71189 CVE-2026-71302 CVE-2026-71379 CVE-2026-72507 CVE-2026-72510

Also covered