<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – MySQL</title>
  <link>https://cvedaily.com/pages/tags/mysql.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/mysql.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – MySQL</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:35 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-25879 – Langroid is a framework for building large-language-model-powered applications. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25879</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25879</strong></p>
  <p>Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabling code execution or filesystem access (e.g., PostgreSQL pg_execute_server_program, MySQL FILE, MSSQL xp_cmdshell), an attacker who can shape…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48188 – An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48188</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48188</strong></p>
  <p>An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the NO_BACKSLASH_ESCAPES SQL mode.  This issue affects OTRS:     *  7.0.X   *  8.0.X   *  2023.X   *  2024.X   *  2025.X   *  2026…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43917 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43917</guid>
    <pubDate>Fri, 29 May 2026 18:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43917</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware only verifies the user is authenticated - it does NOT enforce organization scoping. Each endpoint must individually verify the resource's org matches the session's activeOrganizationId. This affects the following endpoints: allByType, killProcess, and removeDeployment in deploym…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41281 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41281</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41281</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41280 – Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41280</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41280</strong></p>
  <p>Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44635 – Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, Defa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44635</guid>
    <pubDate>Wed, 27 May 2026 19:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44635</strong></p>
  <p>Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlled input flows into eb.ref(col, '->$').key(input) or .at(input) — including type-safe code where the JSON column is shaped like Record<string, T> so K extends string is the inferred type — every dot be…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45717 – Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45717</guid>
    <pubDate>Wed, 27 May 2026 18:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45717</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasourceId is registered in the authorizedRoutes group with TABLE/READ permission. This is the same authorization level as the read endpoint (GET /api/datasources/:datasourceId). Every authenticated Budibase app user with the BASIC built-in role o…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44521 – elFinder is an open-source file manager for web, written in JavaScript using jQu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44521</guid>
    <pubDate>Wed, 27 May 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44521</strong></p>
  <p>elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to inject SQL through a crafted target file hash. Successful exploitation can lead to unauthorized dat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25372 – MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25372</guid>
    <pubDate>Mon, 25 May 2026 15:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25372</strong></p>
  <p>MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the email parameter. Attackers can submit crafted POST requests to the userSignup.php endpoint with SQL payloads in the email field to extract sensitive database information from the backend MySQL database.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48242 – Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection cre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48242</guid>
    <pubDate>Thu, 21 May 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48242</strong></p>
  <p>Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the source to obtain valid configuration values that may match deployed installations.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48241 – Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48241</guid>
    <pubDate>Thu, 21 May 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48241</strong></p>
  <p>Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44047 – An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44047</guid>
    <pubDate>Thu, 21 May 2026 08:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44047</strong></p>
  <p>An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial of service.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47959 – WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47959</guid>
    <pubDate>Fri, 15 May 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47959</strong></p>
  <p>WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads to trigger server out-of-memory conditions and MySQL connection errors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47091 – Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk &lt;2.4.0p2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47091</guid>
    <pubDate>Wed, 13 May 2026 10:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47091</strong></p>
  <p>Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whose name matches 'MySQL' or 'MariaDB' (or with write access to a binary referenced by such a service) to execute arbitrary code in the context of the Checkmk agent service, which typically runs as SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44347 – Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44347</guid>
    <pubDate>Tue, 12 May 2026 23:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44347</strong></p>
  <p>Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate the state parameter, which makes it possible for an attacker to trick a user into logging into the attacker's account, possibly convincing them to perform sensitive actions on the attacker's account (such as writing sensitive data to the attacker's SSH target, or logging into an…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-8276 – A flaw has been found in bettercap up to 2.41.5. Affected by this issue is some ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8276</guid>
    <pubDate>Mon, 11 May 2026 06:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8276</strong></p>
  <p>A flaw has been found in bettercap up to 2.41.5. Affected by this issue is some unknown functionality of the file modules/mysql_server/mysql_server.go of the component MySQL Server. Executing a manipulation can lead to integer coercion error. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been publish…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41496 – PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41496</guid>
    <pubDate>Fri, 08 May 2026 14:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41496</strong></p>
  <p>PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLiteConversationStore only. Nine sibling backends — MySQL, PostgreSQL, async SQLite/MySQL/PostgreSQL, Turso, SingleStore, Supabase, SurrealDB — pass table_prefix straight into f-string SQL. Same root cause, same code pattern, same expl…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29080 – A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29080</guid>
    <pubDate>Wed, 06 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29080</strong></p>
  <p>A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbitrary SQL against the backend database through the DID search endpoint (`GET /dids/<scope>/dids/search`). On Oracle deployments attacker-controlled filter keys and values are interpolated directly into `sqlalchemy.text()` via Python `.format()`, completely bypassing parameterizat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42237 – n8n is an open source workflow automation platform. Prior to versions 1.123.32, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42237</guid>
    <pubDate>Mon, 04 May 2026 19:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42237</strong></p>
  <p>n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f2-mcxc-pwjx did not cover the Snowflake node or the legacy MySQL v1 node. Both nodes construct SQL queries by directly interpolating user-controlled table names, column names, and update keys into query strings without identifier escaping, enabling SQL injection against the conn…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6524 – MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6524</guid>
    <pubDate>Thu, 30 Apr 2026 07:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6524</strong></p>
  <p>MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-3960 – A critical remote code execution vulnerability exists in the unauthenticated RES...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3960</guid>
    <pubDate>Thu, 23 Apr 2026 10:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-3960</strong></p>
  <p>A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blacklist mechanism, which only targets MySQL JDBC driver-specific dangerous parameters. An attacker can bypass these controls by switching the JDBC URL protocol to jdb…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41229 – Froxlor is open source server administration software. Prior to version 2.3.6, `...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41229</guid>
    <pubDate>Thu, 23 Apr 2026 04:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41229</strong></p>
  <p>Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permission adds or updates a MySQL server via the API, the `privileged_user` parameter (which has no input validation) is written unescaped into `lib/u…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35240 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35240</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35240</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35239 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35239</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35239</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35238 – Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35238</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35238</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or fr…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35237 – Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35237</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35237</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or fr…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35236 – Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35236</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35236</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or fr…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35235 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35235</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35235</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS).  Supported versions that are affected are 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35234 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35234</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35234</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Partition).  Supported versions that are affected are 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34319 – Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34319</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34319</strong></p>
  <p>Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell.  Successful attacks require human interaction from a person other than t…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-204</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34318 – Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34318</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34318</strong></p>
  <p>Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Shell.  While the vulnerability is in MySQL Shell, attacks may significantly impact additiona…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34317 – Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34317</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34317</strong></p>
  <p>Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell.  Successful attacks require human interaction from a person other than t…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34308 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34308</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34308</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34304 – Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34304</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34304</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or fr…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34303 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34303</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34303</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34293 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34293</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34293</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34278 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34278</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34278</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34276 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Gr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34276</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34276</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized abil…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34272 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34272</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34272</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable c…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34271 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Gr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34271</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34271</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized abil…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34270 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Gr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34270</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34270</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34270</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized abil…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34270">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34267 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34267</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34267</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22017 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22017</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22017</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22015 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22015</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22015</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized read acce…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22009 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22009</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22009</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22005 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22005</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22005</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22004 – Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22004</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22004</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or fr…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22002 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22002</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22002</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-22001 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22001</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-22001</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized read acc…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21998 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21998</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21998</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40887 – Vendure is an open-source headless commerce platform. Starting in version 1.7.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40887</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40887</strong></p>
  <p>Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the dat…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40899 – DataEase is an open-source data visualization and analytics platform. Versions 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40899</guid>
    <pubDate>Thu, 16 Apr 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40899</strong></p>
  <p>DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mysql class uses Lombok's @Data annotation, which auto-generates a public setter for the illegalParameters field that contains the JDBC security blocklist. When a datasource configuration is submitted as…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-183</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33121 – DataEase is an open-source data visualization and analytics platform. Versions 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33121</guid>
    <pubDate>Thu, 16 Apr 2026 19:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33121</strong></p>
  <p>DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource saving process. The deTableName field from the Base64-encoded datasource configuration is used to construct a DDL statement via simple string replacement without any sanitization or escaping of the table name. An authenticated attacker can in…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30778 – The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configurat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30778</guid>
    <pubDate>Wed, 15 Apr 2026 11:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30778</strong></p>
  <p>The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.  This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0.  Users are recommended to upgrade to version 10.4.0, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-202</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-15441 – The Form Maker by 10Web  WordPress plugin before 1.15.38 does not properly prepa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15441</guid>
    <pubDate>Mon, 13 Apr 2026 07:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-15441</strong></p>
  <p>The Form Maker by 10Web  WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-29861 – PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29861</guid>
    <pubDate>Fri, 10 Apr 2026 15:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-29861</strong></p>
  <p>PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1233 – The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1233</guid>
    <pubDate>Sat, 04 Apr 2026 12:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1233</strong></p>
  <p>The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_TTS_Remote_Telemetry` class. This makes it possible for unauthenticated attackers to extract and deco…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35168 – OpenSTAManager is an open source management software for technical assistance an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35168</guid>
    <pubDate>Thu, 02 Apr 2026 14:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35168</strong></p>
  <p>OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains a database conflict resolution feature (op=risolvi-conflitti-database) that accepts a JSON array of SQL statements via POST and executes them directly against the database without any validation, allowlist, or sanitizat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28805 – OpenSTAManager is an open source management software for technical assistance an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28805</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28805</guid>
    <pubDate>Thu, 02 Apr 2026 14:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28805</strong></p>
  <p>OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Based Blind SQL Injection through the options[stato] GET parameter. The user-supplied value is read from $superselect['stato'] and concatenated directly into SQL WHERE clauses as a bare expression, without any…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28805">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33643 – SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33643</guid>
    <pubDate>Mon, 30 Mar 2026 16:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33643</strong></p>
  <p>SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the mysqlColumnAsInsert function in file plugins/mysql/lib/column.go.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33468 – Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Ky...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33468</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33468</strong></p>
  <p>Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStringLiteral()` only escapes single quotes by doubling them (`'` → `''`) but does not escape backslashes. When used with the MySQL dialect (where `NO_BACKSLASH_ESCAPES` is OFF by default), an attacker can use a backslash to escape the trailing quote of a string literal, breaking o…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33442 – Kysely is a type-safe TypeScript SQL query builder. In versions 0.28.12 and 0.28...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33442</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33442</strong></p>
  <p>Kysely is a type-safe TypeScript SQL query builder. In versions 0.28.12 and 0.28.13, the `sanitizeStringLiteral` method in Kysely's query compiler escapes single quotes (`'` → `''`) but does not escape backslashes. On MySQL with the default `BACKSLASH_ESCAPES` SQL mode, an attacker can inject a backslash before a single quote to neutralize the escaping, breaking out of the JSON path string litera…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4021 – The Contest Gallery plugin for WordPress is vulnerable to an authentication bypa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4021</guid>
    <pubDate>Tue, 24 Mar 2026 00:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4021</strong></p>
  <p>The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email string in a `WHERE ID = %s` clause instead of the numeric user ID, combined with an unauthenticated key-b…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30849 – Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30849</guid>
    <pubDate>Mon, 23 Mar 2026 20:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30849</strong></p>
  <p>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parameter. Other database backends are not affected, as they do not perform implicit type conversion from string to integer. Using a crafted SOAP en…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25576 – Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25576</guid>
    <pubDate>Sat, 21 Mar 2026 16:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25576</strong></p>
  <p>Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the category parameter. Attackers can send GET requests to the category endpoint with URL-encoded SQL UNION statements to extract database information including usernames, database names, and MySQL version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32710 – MariaDB server is a community developed fork of MySQL server. An authenticated u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32710</guid>
    <pubDate>Fri, 20 Mar 2026 19:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32710</strong></p>
  <p>MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab enviro…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32949 – SQLBot is an intelligent data query system based on a large language model and R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32949</guid>
    <pubDate>Fri, 20 Mar 2026 05:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32949</strong></p>
  <p>SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system and application files from the server. An attacker can exploit the /api/v1/datasource/check endpoint by configuring a forged MySQL data source with a malicious parameter extraJdbc…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32763 – Kysely is a type-safe TypeScript SQL query builder. Versions up to and including...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32763</guid>
    <pubDate>Fri, 20 Mar 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32763</strong></p>
  <p>Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerability in JSON path compilation for MySQL and SQLite dialects. The `visitJSONPathLeg()` function appends user-controlled values from `.key()` and `.at()` directly into single-quoted JSON path string literals (`'$.key'`) without escaping single quotes. An attacker can break out of th…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29096 – SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29096</guid>
    <pubDate>Thu, 19 Mar 2026 23:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29096</strong></p>
  <p>SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, when creating or editing a report (AOR_Reports module), the `field_function` parameter from POST data is saved directly into the `aor_fields` table without any validation. Later, when the report is executed/viewed, this value is concatenated directly into a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32628 – AnythingLLM is an application that turns pieces of content into context that any...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32628</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32628</strong></p>
  <p>AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL injection vulnerability in the built-in SQL Agent plugin allows any user who can invoke the agent to execute arbitrary SQL commands on connected databases. The getTableSchemaSql() method in all three database connectors (MySQL, PostgreSQL, MSSQL)…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27005 – Chartbrew is an open-source web application that can connect directly to databas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27005</guid>
    <pubDate>Fri, 06 Mar 2026 05:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27005</strong></p>
  <p>Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3, an unauthenticated attacker can inject arbitrary SQL into queries executed against databases connected to Chartbrew (MySQL, PostgreSQL). This allows reading, modifying, or deleting data in those databases depending on the database user's privileges…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27969 – Vitess is a database clustering system for horizontal scaling of MySQL. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27969</guid>
    <pubDate>Thu, 26 Feb 2026 02:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27969</strong></p>
  <p>Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that files in the manifest — which may be files that they have also added to the manifest and backup contents — are written to any accessible location on restore. This i…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27965 – Vitess is a database clustering system for horizontal scaling of MySQL. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27965</guid>
    <pubDate>Thu, 26 Feb 2026 02:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27965</strong></p>
  <p>Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbitrary code is later executed when that backup is restored. This can be used to provide that attacker with unintended/unauthorized access to the production deplo…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26186 – Fleet is open source device management software. A SQL injection vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26186</guid>
    <pubDate>Thu, 26 Feb 2026 00:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26186</strong></p>
  <p>Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbitrary SQL expressions via the `order_key` query parameter. Due to unsafe use of `goqu.I()` when constructing the `ORDER BY` clause, specially crafted input could escape identifier quoting and be interpreted as executable SQL. An authenticated attacke…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48928 – Piwigo is an open source photo gallery application for the web. In versions on t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48928</guid>
    <pubDate>Tue, 24 Feb 2026 17:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48928</strong></p>
  <p>Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration parameter is set to MD5(RAND()) in MySQL. However, RAND() only has 30 bits of randomness, making it feasible to brute-force the secret key. The CSRF token is constructed partially from the secret key, and this can be used to check if the brute force succeed…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26992 – LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26992</guid>
    <pubDate>Fri, 20 Feb 2026 03:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26992</strong></p>
  <p>LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a port group, an HTTP POST request is sent to the Request-URI "/port-groups". The name of the newly created port group is stored in the value…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26991 – LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26991</guid>
    <pubDate>Fri, 20 Feb 2026 03:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26991</strong></p>
  <p>LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a device group, an HTTP POST request is sent to the Request-URI "/device-groups". The name of the newly created device group is stored in t…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27016 – LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27016</guid>
    <pubDate>Fri, 20 Feb 2026 02:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27016</strong></p>
  <p>LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping. This issue is fixed i…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26990 – LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26990</guid>
    <pubDate>Fri, 20 Feb 2026 02:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26990</strong></p>
  <p>LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Based Blind SQL Injection vulnerability in address-search.inc.php via the address parameter. When a crafted subnet prefix is supplied, the prefix value is concatenated directly into an SQL query without proper parameter binding, allowing an attacker to manipulate query logic and in…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26989 – LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26989</guid>
    <pubDate>Fri, 20 Feb 2026 02:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26989</strong></p>
  <p>LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are affected by a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Rules workflow. An attacker with administrative privileges can inject malicious scripts that execute in the browser context of any user who accesses the Alert Rules page. This issue has been fixed in version 26.2.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26988 – LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26988</guid>
    <pubDate>Fri, 20 Feb 2026 02:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26988</strong></p>
  <p>LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in the ajax_table.php endpoint. The application fails to properly sanitize or parameterize user input when processing IPv6 address searches. Specifically, the address parameter is split into an address and a prefix, and the prefix portion is directly conc…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26987 – LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26987</guid>
    <pubDate>Fri, 20 Feb 2026 02:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26987</strong></p>
  <p>LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to  Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-26958 – filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26958</guid>
    <pubDate>Thu, 19 Feb 2026 23:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-26958</strong></p>
  <p>filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographic primitives. In versions 1.1.0 and earlier, MultiScalarMult produces invalid results or undefined behavior if the receiver is not the identity point. If (*Point).MultiScalarMult is called on an initialized point that is not the identity point, it returns an incorrect result. If…</p>
  <p><strong>CVSS:</strong> 1.7 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-15585 – Fileflows versions before 25.05.2 are affected by an authenticated SQL injection...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15585</guid>
    <pubDate>Thu, 19 Feb 2026 00:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-15585</strong></p>
  <p>Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file search function. Successful exploitation requires the system to use MySQL as the underlying database and could result in privilege escalation or data exfiltration.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55210 – FreePBX is an open-source web-based graphical user interface (GUI) that manages ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55210</guid>
    <pubDate>Thu, 12 Feb 2026 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55210</strong></p>
  <p>FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) is vulnerable to privilege escalation by authenticated users with REST/GraphQL API access. This vulnerability allows an attacker to forge a valid JWT with full access to the REST and GraphQL APIs on a FreePBX that they've already connected to, possibl…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-270</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25923 – my little forum is a PHP and MySQL based internet forum that displays the messag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25923</guid>
    <pubDate>Mon, 09 Feb 2026 22:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25923</strong></p>
  <p>my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attackers to upload a malicious Phar Polyglot file (disguised as JPEG) via the image upload feature, trigger Phar deserialization through BBCode [img] tag processing, and exploit Smarty…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37116 – GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37116</guid>
    <pubDate>Tue, 03 Feb 2026 18:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37116</strong></p>
  <p>GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploading a shell, view the config.php file to obtain the MySQL password, leading to full database compromise.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24479 – HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24479</guid>
    <pubDate>Tue, 27 Jan 2026 01:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24479</strong></p>
  <p>HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj.php and problem_import_hoj.php modules fail to properly sanitize filenames within uploaded ZIP archives. Attackers can craft a malicious ZIP file containing files with path traversal sequences (e.g., ../../shell.php). When extracted by the server,…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23873 – hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23873</guid>
    <pubDate>Thu, 22 Jan 2026 00:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23873</strong></p>
  <p>hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Formula Injection) through the contest rank export functionality (contestrank.xls.php and admin/ranklist_export.php). The application fails to sanitize user-supplied input (specifically the "Nickname" field) before exporting it to an .xls file (which ren…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-1236</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21968 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21968</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21968</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-21965 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21965</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-21965</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21964 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21964</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21964</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to ca…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21952 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21952</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21952</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable cra…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21950 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21950</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21950</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable c…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21949 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21949</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21949</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable c…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21948 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21948</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21948</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21941 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21941</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21941</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21937 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DD...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21937</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21937</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21936 – Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21936</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21936</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or fr…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21929 – Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21929</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21929</strong></p>
  <p>Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser).  Supported versions that are affected are 9.0.0-9.5.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable cr…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21929">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
