CVE-2026-45535
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL
CVSS
—
No CVSS
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Published: Jul 15, 2026 · Last modified: Jul 16, 2026 · CWE-89
0.2%EPSS · 30 days0.2%
2026-07-162026-07-20
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL variable defaultValue entries such as ${var} and SqlparserUtils.handleVariableDefaultValue() inserts them with String.replace() without escaping or parameterization, causing stored SQL injection whenever a user with dataset read permission accesses the dataset. This issue is fixed in version 2.10.23.
- github.comhttps://github.com/dataease/dataease/commit/22930a493d900fe3d8084b3dd4c0125abdb2a847
- github.comhttps://github.com/dataease/dataease/releases/tag/v2.10.23
- github.comhttps://github.com/dataease/dataease/security/advisories/GHSA-pv23-p64m-4pxf
- github.comhttps://github.com/dataease/dataease/security/advisories/GHSA-pv23-p64m-4pxf
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-422089.8 CRI99.7%
KEV—80BerriAI LiteLLM SQL Injection Vulnerability6dCVE-2020-249139.8 CRI98.5%
——30A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.12dCVE-2026-479927.2 HIG97.1%
——29Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction.5dCVE-2022-366358.8 HIG96.7%
——29ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.12dCVE-2023-409316.5 MED95.5%
——29A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php12dCVE-2026-12075.4 MED94.9%
——28An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Tarek Nakkouch for reporting this issue.6d