VYPR

CWE-943

Improper Neutralization of Special Elements in Data Query Logic

ClassIncomplete

Description

The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-676

CVEs mapped to this weakness (113)

page 5 of 6
  • CVE-2026-82060MedSep 8, 2026
    risk 0.35cvss 5.4epss 0.00

    In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with specially crafted, operator-shaped objects as shard key values in sharded collections. When change stream events for such documents were…

  • CVE-2026-85167MedSep 3, 2026
    risk 0.35cvss 6.5epss 0.00

    n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression values directly into the query string before…

  • CVE-2026-63138MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the…

  • CVE-2026-81528MedAug 27, 2026
    risk 0.35cvss 5.4epss 0.00

    A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a value supplied as a replacement is forwarded to the server without neutralization of query-language special elements. An application that passes…

  • CVE-2026-40102MedMay 20, 2026
    risk 0.35cvss 6.5epss 0.00

    Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the regular AnalyticsEndpoint, which checks against an…

  • CVE-2026-42316MedMay 11, 2026
    risk 0.35cvss 6.5epss 0.00

    kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the kusto.tables.topics.mapping configuration. The db, table, mapping, and format…

  • CVE-2026-25591MedFeb 24, 2026
    risk 0.35cvss 6.5epss 0.01

    New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service…

  • CVE-2021-34712MedSep 23, 2021
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input validation by the…

  • CVE-2026-56096MedAug 25, 2026
    risk 0.34cvss —epss 0.00

    The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to enumerate indexed field names and extract…

  • CVE-2026-34973MedApr 2, 2026
    risk 0.34cvss 5.3epss 0.00

    phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the searchCustomPages() method in phpmyfaq/src/phpMyFAQ/Search.php uses real_escape_string() (via escape()) to sanitize the search term before embedding it in LIKE clauses. However, real_escape_string() does…

  • CVE-2026-30833MedMar 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, a NoSQL injection vulnerability exists in Rocket.Chat's account service used in the ddp-streamer micro service that…

  • CVE-2025-33114MedJul 29, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to denial of service with a specially crafted query under certain non-default conditions.

  • CVE-2024-35136MedAug 14, 2024
    risk 0.34cvss 5.3epss 0.01

    IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain non default conditions. IBM X-Force ID: 291307.

  • CVE-2024-31882MedAug 14, 2024
    risk 0.34cvss 5.3epss 0.01

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user. IBM X-Force ID: …

  • CVE-2024-28192MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.01

    your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQL injection in the public access token processing logic. Attackers can fully bypass the public token authentication mechanism, regardless if a public token has…

  • CVE-2026-41697MedJun 10, 2026
    risk 0.31cvss 4.8epss 0.00

    Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An attacker can supply wildcard characters to perform boolean-based blind data inference. Affected…

  • CVE-2026-41696MedJun 10, 2026
    risk 0.31cvss 5.9epss 0.00

    Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expression quoting. Affected versions: Spring…

  • CVE-2025-23292MedSep 30, 2025
    risk 0.30cvss 4.6epss 0.00

    NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to partial denial of service (UI component).

  • CVE-2026-59319MedAug 27, 2026
    risk 0.28cvss 4.3epss 0.00

    RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values without applying RediSearchUtil.escape(), unlike get(), clear(), and findByTimeRange() in the same class which do escape their inputs. An application that…

  • CVE-2026-49482MedJun 12, 2026
    risk 0.28cvss 4.3epss 0.00

    ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the subtitle editing endpoint. An authenticated user can send a % character as the number parameter to overwrite…