---
id: CVE-2026-94143
title: A vulnerability was detected in drogonframework drogon up to 1.9.13
summary: >-
  A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected
  by this issue is the function Mapper::orderBy in the library Mapper.h of the
  component ORM Mapper. Performing a manipulation of the argument sort results
  in sq…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: drogonframework
product: drogon
affected:
  - drogon 1.9.0
  - drogon 1.9.1
  - drogon 1.9.2
  - drogon 1.9.3
  - drogon 1.9.4
  - drogon 1.9.5
  - drogon 1.9.6
  - drogon 1.9.7
  - drogon 1.9.8
  - drogon 1.9.9
  - drogon 1.9.10
  - drogon 1.9.11
  - drogon 1.9.12
  - drogon 1.9.13
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T22:16:59.717'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94143'
references:
  - url: 'https://gist.github.com/2H-K/33f46c954fd3ed16b32eeddd598f90cf'
    label: cna@vuldb.com
  - url: 'https://github.com/drogonframework/drogon/'
    label: cna@vuldb.com
  - url: 'https://github.com/drogonframework/drogon/issues/2575'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-94143'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/893923'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408058'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408058/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T10:28:46.473901Z'
epss: 0.00435
epssPercentile: 0.35144
ingestedAt: '2026-09-21T05:31:59.918Z'
---

## Overview

A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the component ORM Mapper. Performing a manipulation of the argument sort results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
