A vulnerability described as critical has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of the file /users/contact_us.php. Executing a manipulation of the argument Name can lead to sql injection.

This vulnerability is tracked as CVE-2026-5805. The attack can be launched remotely. Moreover, an exploit is present.