{"id":"CVE-2026-85215","title":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc","summary":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection.\n\nThis issue affects Paperwork: through 2026-09-09.","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-89"],"vendor":"GG Soft Software Services Inc.","product":"Paperwork","affected":["Paperwork <= 2026-09-09"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T14:30:51.640","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85215","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1244","label":"iletisim@usom.gov.tr"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T14:20:32.573Z","slug":"CVE-2026-85215","body":"## Overview\n\nImproper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection.\n\nThis issue affects Paperwork: through 2026-09-09.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}