CWE-943: Improper Neutralization of Special Elements in Data Query Logic
The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
87 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-4872 — A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an
- CVE-2026-32248 — Parse Server: Account takeover via operator injection in authentication data identifier
- CVE-2026-30941 — Parse Server has a NoSQL injection via token type in password reset and email verification endpoints
- CVE-2026-25514 — FacturaScripts has SQL Injection vulnerability in Autocomplete Actions
- CVE-2025-24787 — Parameter injection in DB connection URIs leading to local file inclusion in WhoDB
- CVE-2026-54350 — Budibase: Anonymous NoSQL operator injection via published-app query templates
- CVE-2026-33980 — Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
- CVE-2026-25513 — FacturaScripts has SQL Injection vulnerability in API ORDER BY Clause
- CVE-2026-40351 — FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass
- CVE-2026-32247 — Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
- CVE-2026-41274 — Flowise: Cypher Injection in GraphCypherQAChain
- CVE-2026-29793 — NoSQL Injection via WebSocket id Parameter in MongoDB Adapter
- CVE-2026-27886 — Strapi may leak sensitive data via relational filtering due to lack of query sanitization
- CVE-2026-45689 — Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO
- CVE-2026-45688 — Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session Hijack
- CVE-2026-41328 — Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
- CVE-2026-41327 — Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
- CVE-2026-76316 — Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise
- CVE-2026-40352 — FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeover
- CVE-2026-47181 — PenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Account Takeover
Recently published
- CVE-2026-82060 — Insufficient Validation of Shard Key Values in MongoDB Server Leads to Query Operator Injection in Change Stream Post-Image Lookups
- CVE-2026-85167 — n8n before 2.36.2 Query Injection via Elasticsearch Firestore Nodes
- CVE-2026-63138 — Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information Disclosure
- CVE-2026-78691 — Unescaped backslash allows LIKE wildcard injection in AshSql string search
- CVE-2026-77846 — JSON path injection via unescaped get_path segments in AshSqlite
- CVE-2026-81528 — NoSQL injection via array replacement bypassing update shape validation in driver write path
- CVE-2026-81527 — NoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translation
- CVE-2026-81525 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP Driver
- CVE-2026-56094 — Information Disclosure in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
- CVE-2026-56096 — Information Disclosure in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
- CVE-2026-77070 — n8n before 1.123.69 NoSQL Injection via MongoDB Node
- CVE-2026-76363 — Structured Query Language Injection through the REST API in Splunk SOAR
- CVE-2026-76349 — SPL Injection through Splunk Web Form Tokens in Splunk Enterprise
- CVE-2026-76331 — SPL Injection through the REST API in Splunk Enterprise
- CVE-2026-76329 — SPL Injection through Monitoring Console Dashboard Inputs in Splunk Enterprise
- CVE-2026-76327 — SPL Injection through Splunk Web in Splunk Secure Gateway
- CVE-2026-76320 — SPL Injection through Cross-Site Request Forgery (CSRF) in the Event Type Builder in Splunk Web for Splunk Enterprise
- CVE-2026-76316 — Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise
- CVE-2026-76254 — SPL Command Safeguards Bypass through Splunk Web in Splunk Enterprise
- CVE-2026-73618 — Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter