<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Hibernate ORM (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/hibernate-orm.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/hibernate-orm-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Hibernate ORM (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:58 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-4594 – A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4594</guid>
    <pubDate>Mon, 23 Mar 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4594</strong></p>
  <p>A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy of the file erupt-data/erupt-jpa/src/main/java/xyz/erupt/jpa/dao/EruptJpaUtils.java. Such manipulation of the argument sort.field leads to sql injection hibernate. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The ven…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0603 – A flaw was found in Hibernate. A remote attacker with low privileges could explo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0603</guid>
    <pubDate>Fri, 23 Jan 2026 07:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0603</strong></p>
  <p>A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the app…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10968 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10968</guid>
    <pubDate>Fri, 07 Nov 2025 13:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10968</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in GG Soft Software Services Inc. PaperWork allows Blind SQL Injection, SQL Injection.This issue affects PaperWork: from 6.1.0.9390 before 6.1.0.9398.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54385 – XWiki Platform is a generic wiki platform offering runtime services for applicat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54385</guid>
    <pubDate>Sat, 26 Jul 2025 04:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54385</strong></p>
  <p>XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions between 17.0.0-rc1 to 17.2.2 and versions 16.10.5 and below, it's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGEN or DBMS_XMLQUERY. The XWiki#searchDocuments APIs pass queries directly to Hibernate without sanitization. Even when these APIs enforc…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-56158 – XWiki is a generic wiki platform. It's possible to execute any SQL query in Orac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56158</guid>
    <pubDate>Thu, 12 Jun 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-56158</strong></p>
  <p>XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGEN or DBMS_XMLQUERY. The XWiki query validator does not sanitize functions that would be used in a simple select and Hibernate allows using any native function in an HQL query. This vulnerability is fixed in 16.10.2, 16.4.7, and 15.10.16.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-7071 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7071</guid>
    <pubDate>Tue, 27 Aug 2024 14:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-7071</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain Low-Code allows SQL Injection.  This issue affects Brain Low-Code: before 2.1.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-26093 – Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26093</guid>
    <pubDate>Mon, 20 Feb 2023 05:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-26093</strong></p>
  <p>Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-4997 – gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4997</guid>
    <pubDate>Tue, 07 Sep 2010 18:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-4997</strong></p>
  <p>gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532.  NOTE: this issue exists because of a regression that followed a gnome-p…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-4996 – Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4996</guid>
    <pubDate>Tue, 07 Sep 2010 18:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-4996</strong></p>
  <p>Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532.  NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, b…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-7240 – gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7240</guid>
    <pubDate>Tue, 07 Sep 2010 18:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-7240</strong></p>
  <p>gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-2532 – lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-2532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-2532</guid>
    <pubDate>Fri, 03 Sep 2010 20:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-2532</strong></p>
  <p>lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other platforms, does not lock the screen when the Suspend or Hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-2532">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
