A vulnerability, which was classified as critical, has been found in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the function fwrite of the file admin/pageMail.php. The manipulation of the argument mailSubject/mailMessage leads to command injection.
This vulnerability is listed as CVE-2026-5041. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability classified as problematic was found in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c of the component mxmlIndexNew. Executing a manipulation of the argument tempr can lead to stack-based buffer overflow.
This vulnerability is tracked as CVE-2026-5037. The attack is restricted to local execution. Moreover, an exploit is present.
A patch should be applied to remediate this issue.