Medium severity6.5NVD Advisory· Published May 1, 2026· Updated Jul 8, 2026
CVE-2026-42475
CVE-2026-42475
Description
SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted on array to the joinOn function in BuildHelper.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mix/mixPackagist | >= 2.0.0, <= 2.2.17 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- gist.github.com/sgInnora/fa46386840fe978a30d7e53c458f2975nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-vf35-8m4j-gm8vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-42475ghsaADVISORY
- github.com/mix-php/mix/blob/v2.2.17/src/database/src/Helper/BuildHelper.phpnvdProductWEB
News mentions
0No linked articles in our index yet.