VulnSea

CWE-943

CVEs classified under CWE-943, newest first.

37 CVEsRSS

CVE-2026-93760High· 8.2
3d ago

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this wa…

TwilightMongoDB Inc. · MongoidEPSS 0.28%via NVD
CVE-2026-20284Critical· 9.1⚠ ExploitedPoC
5d ago

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacke…

AbyssalCisco · Cisco Identity Services Engine SoftwareEPSS 0.39%via NVD
CVE-2026-91937High· 7.5
6d ago

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to r…

TwilightFlowiseAI · FlowiseEPSS 0.28%via NVD
CVE-2026-55253High· 7.7
1w ago

LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph

LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search()…

Twilightlangchain-ai · langchain-mongodbEPSS 0.39%via NVD
CVE-2026-88033High· 8.3
1w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Twilightmongodb · java_driverEPSS 0.25%via NVD
CVE-2026-88036High· 8.3
1w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identi…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identi…

Twilightmongodb · c_driverEPSS 0.26%via NVD
CVE-2026-88024High· 8.3
1w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

TwilightMongoDB · Rust DriverEPSS 0.32%via NVD
CVE-2026-88027High· 7.1
1w ago

Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query conditi…

Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query conditi…

TwilightMongoDB · Laravel MongoDB (PHP)EPSS 0.23%via NVD
CVE-2026-88030High· 8.3
1w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

TwilightMongoDB · Ruby DriverEPSS 0.26%via NVD
CVE-2026-88028Medium· 6.5
1w ago

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather tha…

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather tha…

SunlitMongoDB · Laravel MongoDB (PHP)EPSS 0.24%via NVD
CVE-2026-88031High· 8.1
1w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

TwilightMongoDB · Go DriverEPSS 0.26%via NVD
CVE-2026-88029High· 8.3
1w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal i…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal i…

TwilightMongoDB · Python DriverEPSS 0.26%via NVD
CVE-2026-88023High· 8.3
1w ago

GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB PHP Library

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

TwilightMongoDB · MongoDB PHP LibraryEPSS 0.32%via CVEORG
CVE-2026-88022High· 7.7
1w ago

Unauthorized document disclosure and deletion via query-operator injection in explicit equality filters in MongoDB integration for Laravel

Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter to be interpreted as a query condition rather than as a literal value. This…

TwilightMongoDB · Laravel MongoDB (PHP)EPSS 0.30%via CVEORG
CVE-2026-88026Medium· 6.5
1w ago

Regular expression injection via unescaped characters in LINQ query translation in MongoDB C# Driver

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected…

SunlitMongoDB · C# DriverEPSS 0.22%via CVEORG
CVE-2026-88025High· 8.3
1w ago

GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# Driver

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

TwilightMongoDB · C# DriverEPSS 0.32%via CVEORG
CVE-2026-88034High· 8.3
1w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal iden…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal iden…

Twilightmongodb · c++_driverEPSS 0.25%via NVD
CVE-2026-81525High· 8.1
1w ago

mongodb: Reject "." and NUL bytes in database and collection names

mongodb: Reject "." and NUL bytes in database and collection names

Twilightmongodb · mongodb/mongodbEPSS 0.27%via GHSA
CVE-2026-82060Medium· 5.4
1w ago

In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with specially crafted, operator-shaped objects as shard key values in sharded collections

In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with specially crafted, operator-shaped objects as shard key values in sharded collections. When change stre…

Sunlitmongodb · mongodbEPSS 0.23%via NVD
CVE-2026-85167Medium· 6.5
2w ago

n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression value…

n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression value…

Sunlitn8n · n8nEPSS 0.23%via NVD
CVE-2026-62906High· 7.4
2w ago

Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft Discovery StudioEPSS 0.67%via NVD
CVE-2026-78691None
3w ago

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, t…

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, t…

SunlitEPSS 0.14%via NVD
CVE-2026-77846None
3w ago

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested JSON the application never exposed, disclosing private o…

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested JSON the application never exposed, disclosing private o…

SunlitEPSS 0.14%via NVD
CVE-2026-59319Medium· 4.3
3w ago

RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values without applying RediSearchUtil.escape(), unlike get(), clear(), and findByTimeRange() in the same class which do esca…

RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values without applying RediSearchUtil.escape(), unlike get(), clear(), and findByTimeRange() in the same class which do esca…

SunlitEPSS 0.22%via NVD
CVE-2026-56096Medium· 6.3PoC
3w ago

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to e…

TwilightTYPO3 · apache-solr-for-typo3/solrEPSS 0.33%via NVD
CVE-2026-56094Medium· 6.3
3w ago

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a…

SunlitTYPO3 · apache-solr-for-typo3/solrEPSS 0.26%via NVD
CVE-2026-70395None
1mo ago

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_re…

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_re…

SunlitEPSS 0.14%via NVD
CVE-2026-63637High· 8.6
1mo ago

Dgraph is an open source distributed GraphQL database

Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing cr…

TwilightEPSS 0.25%via NVD
CVE-2026-48121Medium· 6.7
1mo ago

@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage

@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, c…

Sunlitlangchain · @langchain/langgraph-checkpoint-mongodbEPSS 0.23%via NVD
GHSA-pqh8-p93p-2rx7Medium· 4.3
1mo ago

@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL

@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL

Sunlitdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
CWE-943 vulnerabilities (CVEs) · VulnSea