CWE-943
CVEs classified under CWE-943, newest first.
37 CVEsRSS
GHSA-qw6m-8fw2-2v64High· 8.3Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
GHSA-5c7w-4wm3-85vwMedium@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection
@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection
CVE-2026-44840High· 7.5PoCDgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
CVE-2026-54350Critical· 10.0PoCBudibase has nonymous NoSQL operator injection via published-app query templates
Budibase has nonymous NoSQL operator injection via published-app query templates
CVE-2026-54019Medium· 6.5Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
CVE-2026-41697Medium· 4.8Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE)
Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An attacker can supply wildcard characters to perform boo…
CVE-2026-41696Medium· 5.9Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter
Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expr…