CVE-2026-27851
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabli
CVSS
7.4
Alto
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Publicado: 12 may 2026 · Última mod.: 15 jul 2026 · CWE-235 · CWE-89
0.4%EPSS · 30 días0.4%
2026-08-262026-09-23
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.
- documentation.open-xchange.comhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0002.json
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-27851
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2476471
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27851.json
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-956019.3 CRÍ—
——0Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.6hCVE-2026-955937.6 ALT—
——0Editor SQL Injection in Ultimeter <= 3.0.8 versions.6hCVE-2026-955907.1 ALT—
——0Subscriber SQL Injection in Tainacan <= 1.2.0 versions.6hCVE-2026-955227.6 ALT—
——0Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.6hCVE-2026-941747.6 ALT—
——0Administrator SQL Injection in Email Log <= 2.63 versions.6hCVE-2026-941248.5 ALT—
——0Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.6h