Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

84 advisories

Loading
@nocobase/database has SQL Injection via String Concatenation through Recursive Eager Loading High
CVE-2026-41640 was published for @nocobase/database (npm) Apr 22, 2026
p80n-sec Credited to p80n-sec
@nocobase/plugin-collection-sql: SQL Validation Bypass Through Missing `checkSQL` Call High
CVE-2026-41641 was published for @nocobase/plugin-collection-sql (npm) Apr 22, 2026
p80n-sec Credited to p80n-sec
Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId) Critical
CVE-2026-41478 was published for @saltcorn/server (npm) Apr 16, 2026
QiaoNPC Credited to QiaoNPC
@vendure/core has a SQL Injection vulnerability Critical
CVE-2026-40887 was published for @vendure/core (npm) Apr 14, 2026
jacobfrantz1 Credited to jacobfrantz1
@saltcorn/data vulnerable to SQL Injection via jsexprToSQL Literal Handler Low
GHSA-59xv-588h-2vmm was published for @saltcorn/data (npm) Apr 10, 2026
zulloper Credited to zulloper
Drizzle ORM has SQL injection via improperly escaped SQL identifiers High
CVE-2026-39356 was published for drizzle-orm (npm) Apr 8, 2026
EthanKim88 Credited to EthanKim88 and 0x90sh 0x90sh 0x90sh
NocoBase Has SQL Injection via template variable substitution in workflow SQL node High
CVE-2026-34825 was published for @nocobase/plugin-workflow-sql (npm) Apr 1, 2026
Payload has an SQL Injection via Query Handling High
CVE-2026-34747 was published for payload (npm) Apr 1, 2026
hessandrew Credited to hessandrew and arkmarta arkmarta arkmarta
MikroORM is vulnerable to SQL Injection via specially crafted object Critical
CVE-2026-34220 was published for @mikro-orm/core (npm) Mar 29, 2026
lukas-eu Credited to lukas-eu
n8n has SQL Injection in Data Table Node via orderByColumn Expression High
CVE-2026-33713 was published for n8n (npm) Mar 26, 2026
CodeByMoriarty Credited to CodeByMoriarty
n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode Critical
CVE-2026-33660 was published for n8n (npm) Mar 25, 2026
duddnr0615k Credited to duddnr0615k, simonkoeck, c0rydoras, and nil340 simonkoeck simonkoeck
c0rydoras c0rydoras nil340 nil340
Parse Server has SQL Injection through aggregate and distinct field names in PostgreSQL adapter High
CVE-2026-33539 was published for parse-server (npm) Mar 24, 2026
mtrezza Credited to mtrezza
offset Credited to offset and igalklebanov igalklebanov igalklebanov
vnykmshr Credited to vnykmshr
EthanKim88 Credited to EthanKim88 and igalklebanov igalklebanov igalklebanov
OneUptime ClickHouse SQL Injection via Aggregate Query Parameters Critical
CVE-2026-32306 was published for oneuptime (npm) Mar 13, 2026
offset Credited to offset
Parse Server has a SQL injection via query field name when using PostgreSQL Moderate
CVE-2026-32234 was published for parse-server (npm) Mar 12, 2026
0xkakash1 Credited to 0xkakash1 and mtrezza mtrezza mtrezza
Parse Server vulnerable to SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL Critical
CVE-2026-31871 was published for parse-server (npm) Mar 11, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
Parse Server vulnerable to SQL injection via `Increment` operation on nested object field in PostgreSQL Critical
CVE-2026-31856 was published for parse-server (npm) Mar 11, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type High
CVE-2026-30951 was published for sequelize (npm) Mar 11, 2026
EthanKim88 Credited to EthanKim88
Parse Server: SQL injection via dot-notation field name in PostgreSQL Critical
CVE-2026-31840 was published for parse-server (npm) Mar 10, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
NocoDB Vulnerable to SQL Injection via DATEADD Formula Moderate
CVE-2026-28399 was published for nocodb (npm) Mar 3, 2026
q1uf3ng Credited to q1uf3ng
n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes Moderate
GHSA-f3f2-mcxc-pwjx was published for n8n (npm) Feb 26, 2026
n8n has Potential Remote Code Execution via Merge Node Critical
CVE-2026-27497 was published for n8n (npm) Feb 25, 2026
allsmog Credited to allsmog and nil340 nil340 nil340
ProTip! Advisories are also available from the GraphQL API