A vulnerability categorized as critical has been discovered in code-projects Lost and Found Thing Management 1.0. Affected by this issue is some unknown functionality of the file /catageory.php. Such manipulation of the argument cat leads to sql injection.

This vulnerability is referenced as CVE-2026-6163. It is possible to launch the attack remotely. Furthermore, an exploit is available.