Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-34100
Guardian Language-System SQL Injection via id Parameter in media.php
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 8.7 .0046 37.3 —
AFFECTED
Product Versions Fixed
language-system unspecified —
TIMELINE
Mar 25 Reserved by VulnCheck
Jul 1 Published (CNA: VulnCheck)
Aug 23 EXPLOIT PUBLISHED — CVE-2026-34100 (guardian language-system). Public exploit reference added.
Aug 24 EXPLOIT PUBLISHED — CVE-2026-34100 (guardian language-system). Public exploit reference added.
Aug 24 RESCORED — CVE-2026-34100 (guardian language-system). CVSS 9.3 → 8.7 (NVD).
Description
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents.
Lifecycle
Complete event history — 5 events, chronological
| Date | Event | Detail |
| March 25, 2026 | Reserved | Reserved by VulnCheck |
| July 1, 2026 | Published | Published (CNA: VulnCheck) |
| August 23, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-34100 (guardian language-system). Public exploit reference added. |
| August 24, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-34100 (guardian language-system). Public exploit reference added. |
| August 24, 2026 | RESCORED | RESCORED — CVE-2026-34100 (guardian language-system). CVSS 9.3 → 8.7 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| guardian | language-system | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-34100 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.