CWE-943
Improper Neutralization of Special Elements in Data Query Logic
The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
66 vulnerabilities with CWE-943
CVE-2026-8649
MEDIUM
Progress MOVEit Transfer Custom Reports - Data Query Logic Injection
CVSS 6.4
CVE-2026-10698
HIGH
Progress MOVEit Transfer Custom Reports - Query Logic Injection
CVSS 7.2
CVE-2026-44840
HIGH
Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
CVSS 7.5
CVE-2026-40141
CRITICAL
BeyondTrust Remote Support and PRA - Authenticated Unauthorized Data Access
CVSS 9.9
CVE-2026-46591
HIGH
Apache Camel Neo4j - Cypher Injection via JSON Property Names
CVSS 8.2
CVE-2026-54350
CRITICAL
Budibase: Anonymous NoSQL operator injection via published-app query templates
CVSS 10.0
CVE-2026-45689
CRITICAL
Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO
CVSS 9.1
CVE-2026-45688
CRITICAL
Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session Hijack
CVSS 9.1
CVE-2026-54019
MEDIUM
Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
CVSS 6.5
CVE-2026-47835
HIGH
Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores
CVSS 8.6
CVE-2026-49482
MEDIUM
ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite
CVSS 4.3
CVE-2026-47181
HIGH
PenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Account Takeover
CVE-2026-53674
HIGH
BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution
CVSS 7.1
CVE-2026-41697
MEDIUM
Spring Data Relational Parameter not Escaped for Query By Example LIKE Pattern
CVSS 4.8
CVE-2026-41696
MEDIUM
Spring Data MongoDB Bind Parameter Literal Quoting Breakout
CVSS 5.9
CVE-2026-40102
MEDIUM
Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics
CVSS 6.5
CVE-2026-27886
HIGH
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
CVSS 7.5
CVE-2026-44425
MEDIUM
ShellHub: Crash-DoS via field injection in filter and sort-by parameters
CVSS 5.4
CVE-2026-42156
HIGH
Flowsint: Cypher query injection in node type on node creation
CVE-2026-42316
MEDIUM
KQL injection via kusto.tables.topics.mapping in kafka-sink-azure-kusto
CVSS 6.5
CVE-2026-33566
MEDIUM
LogonTracer <2.0.0 - Cypher Injection
CVSS 4.3
CVE-2026-41328
CRITICAL
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
CVSS 9.1
CVE-2026-41327
CRITICAL
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
CVSS 9.1
CVE-2026-41274
CRITICAL
Flowise: Cypher Injection in GraphCypherQAChain
CVSS 9.8
CVE-2026-6626
MEDIUM
Cockpit-HQ Cockpit Asset Handler/Aggregate data query logic injection
CVSS 6.3
Details
Vulnerabilities
66