Guardian
Guardian Language-system: vulnerabilities and CVEs
Guardian Language-system has 21 published vulnerabilities, 21 of them in the last 12 months. 12 are rated critical and 0 are listed by CISA as actively exploited.
CVEs21
Last 12 months21
Critical12
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34117 | Critical (9.3) | 0.93% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) without sanitization: exec(\"php jobs/text_to_subtitles.php \".$login_session.\" \".$_GET['id'].\"… |
| CVE-2026-34116 | Critical (9.3) | 0.93% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php jobs/transcribe.php \".$login_session.\" \".$_GET['id'].\" ...\"). No… |
| CVE-2026-34115 | Critical (9.3) | 0.93% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) without sanitization: exec(\"php jobs/transcribe_amazon.php \".$login_session.\" \".$_GET['id'].\"… |
| CVE-2026-34114 | Critical (9.3) | 0.93% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) without sanitization: exec(\"php jobs/translate_text.php \".$login_session.\" \".$_GET['id'].\"… |
| CVE-2026-34113 | Critical (9.3) | 0.93% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) without sanitization: exec(\"php jobs/speech_audio_text.php \".$login_session.\" \".$_GET['id'].\"… |
| CVE-2026-34112 | Critical (9.3) | 0.93% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without sanitization: exec(\"php jobs/speech_audio_mac.php \".$login_session.\" \".$_GET['id'].\" ...\").… |
| CVE-2026-34110 | Critical (9.3) | 0.93% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"php jobs/complex.php \".$login_session.\" \".$_GET['id'].\" ...\"). No… |
| CVE-2026-34109 | Critical (9.3) | 0.93% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without sanitization: exec(\"php jobs/speech_audio.php \".$login_session.\" \".$_GET['id'].\" ...\"). No… |
| CVE-2026-34108 | Critical (9.3) | 0.93% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication… |
| CVE-2026-34107 | Critical (9.3) | 0.93% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs/translate.php \".$login_session.\" \".$_GET['id'].\" ...\"). No… |
| CVE-2026-34106 | Critical (9.3) | 0.93% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs/subtitle_rendering.php \".$login_session.\" \".$_GET['id'].\" ...\").… |
| CVE-2026-34105 | High (8.7) | 0.46% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An… |
| CVE-2026-34104 | High (8.7) | 0.46% | — | Jul 1, 2026 | Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE name='\".$_GET['name'].\"'. An authenticated attacker can perform… |
| CVE-2026-34103 | High (8.7) | 0.46% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated… |
| CVE-2026-34102 | High (8.7) | 0.46% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'. An authenticated attacker can perform… |
| CVE-2026-34101 | High (8.7) | 0.46% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id =… |
| CVE-2026-34100 | High (8.7) | 0.46% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id =… |
| CVE-2026-34099 | Critical (9.3) | 0.63% | — | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = '\".$_GET['id'].\"'. No authentication is required. An unauthenticated… |
| CVE-2026-34098 | Medium (4.8) | 0.24% | — | Jul 1, 2026 | Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action attributes in media.php (lines 119, 129). An authenticated attacker can craft a URL that injects… |
| CVE-2026-34097 | Medium (4.8) | 0.24% | — | Jul 1, 2026 | Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attributes in text_file.php (lines 94, 101, 323, 403, 826, 852). An authenticated attacker can craft a… |
| CVE-2026-34096 | Medium (4.8) | 0.24% | — | Jul 1, 2026 | Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribute in designer.php (line 57). An authenticated attacker can craft a URL containing script tags that… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.