S4E just found a critical-severity finding from generic command injection vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2022-46071

9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Updated Sep 26, 2026View on NVD →
S4E scanner

CVE-2022-46071 Scanner

Targets the username parameter of the login endpoint, allowing unauthenticated attackers to bypass authentication and gain admin access.

Used 3.2k times · 3.4k assets checked · domain, ipv4, subdomain

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →