VYPR

SQLView Workflow Template

by KRIS

CVEs (1)

  • CVE-2026-89191MedOct 8, 2026
    risk 0.44cvss 6.8epss —

    Unsanitised input in the "template name" field of SQLView KRIS's Workflow Template feature is rendered in "onclick" attributes on the main dashboard without proper server-side sanitisation, allowing an attacker with administrative access to inject and store malicious scripts…