VYPR
Medium severity6.5NVD Advisory· Published May 1, 2026· Updated May 5, 2026

CVE-2026-42474

CVE-2026-42474

Description

SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted data array to the data function in BuildHelper.php.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mix/mixPackagist
>= 2.0.0, <= 2.2.17

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.