{"error":0,"message":null,"data":{"name":"Relevanssi Premium","plugin":"relevanssi-premium","link":"https:\/\/www.relevanssi.com\/","latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"a20925070ebb231c8c0737fc5c17e9fa8056fb9a2719ea9bcd10fa585b93b720","name":"Relevanssi Premium [relevanssi-premium] < 1.14.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.14.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2016-10949","name":"CVE-2016-10949","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-10949","description":"[en] The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.","date":"2019-09-13"},{"id":"e3f5a960b4fcd9467968a50f256749f137f28180","name":"Relevanssi Premium < 1.14.6.1 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi-premium\/relevanssi-premium-11461-sql-injection","description":"The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.","date":"2016-11-17"},{"id":"5c9b3d02-b23c-4d35-91f3-68570f808237","name":"Relevanssi Premium &lt;= 1.14.4 - SQL Injection &amp; PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/5c9b3d02-b23c-4d35-91f3-68570f808237","description":"The relevanssi-premium WordPress plugin was affected by a SQL Injection &amp; PHP Object Injection security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"633ca12205db24731e4d1d1995e43d6df6f514814df91f7056c31f5dde159034","name":"Relevanssi Premium [relevanssi-premium] < 2.16.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.16.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8bcaea6e3eeb21296de4b173450c6a112af82c53","name":"WordPress Relevanssi Premium plugin <= 2.16.4 - Unauthorized AJAX Calls vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi-premium\/vulnerability\/wordpress-relevanssi-premium-plugin-2-16-4-unauthorized-ajax-calls-vulnerability","description":"Unauthorized AJAX Calls vulnerability discovered by Jan w Oleju in WordPress Relevanssi Premium plugin (versions <= 2.16.4).","date":"2022-02-15"}],"impact":[]},{"uuid":"cdb12bffda29f50da66998c8d29e98baa2722b770467a6585091373cc80fc33d","name":"Relevanssi Premium [relevanssi-premium] < 1.14.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.14.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ed4c8bc92108cf23513491cf01f3dddc6c7b27ff","name":"WordPress Relevanssi Premium Plugin <= 1.14.4 - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi-premium\/vulnerability\/wordpress-relevanssi-premium-plugin-1-14-4-multiple-vulnerabilities","description":"This plugin is prone to a SQL injection and PHP object injection vulnerabilities.\nUpdate the plugin.","date":"2016-11-17"}],"impact":[]},{"uuid":"f959b1a0621226da55c9cde9214f0fdd58c8e22b9a9437bb69ac0464bc11c5ba","name":"Relevanssi Premium [relevanssi-premium] < 2.16.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.16.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c0c27674-715e-464d-ab38-0774128e6741","name":"Relevanssi - Subscriber+ Unauthorised AJAX Calls","link":"https:\/\/wpscan.com\/vulnerability\/c0c27674-715e-464d-ab38-0774128e6741","description":"The plugins do not have authorisation and CSRF checks in some of their AJAX actions, allowing any authenticated users, such as subscriber, to call them. This could disclose information to subscribers, as well as allow them to truncate the index, which will disable the search","date":null}],"impact":[]},{"uuid":"86c0878eb9e4abeabce4da71ea8c0caa20027f0458b4af24fea9d9a6211240a2","name":"Relevanssi Premium [relevanssi-premium] < 2.25.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.25.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8cd51efd1ba1c42a3c6b96e7c8a22b9be30409cf","name":"Relevanssi <= 4.21.2 (Free) and < 2.25.0 (Premium) - Missing Authorization to Unauthorized Post Access","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-4212-free-and-2250-premium-missing-authorization-to-unauthorized-post-access","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to insufficient limitation of a user controlled key in all versions up to, and including, 4.21.2 (Free) and < 2.25.0 (Premium). This makes it possible for unauthenticated attackers to view private and draft posts that may contain sensitive information.","date":"2024-01-04"},{"id":"CVE-2023-7199","name":"CVE-2023-7199","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-7199","description":"[en] The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request","date":"2024-01-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5a24cb3769c85bd1ccb3b04266412fc94e2d600720f6ff23d36a658369835c49","name":"Relevanssi Premium [relevanssi-premium] < 2.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0e0e9e1765f730caa344d856b76c4994a1b90b9d","name":"Relevanssi Pro < 2.25 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi-premium\/relevanssi-pro-225-unauthenticated-sensitive-information-exposure","description":"The Relevanssi \u2013 A Better Search (Pro) plugin for WordPress is vulnerable to Sensitive Information Exposure in versions before 2.25. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2024-01-31"}],"impact":[]},{"uuid":"2ef68c1bc17c56b4aa69d31afde43db59d48442b253aa0edde72497ab6807f04","name":"Relevanssi Premium [relevanssi-premium] < 2.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"083429a9eb5ea59166ddcff5bbbe9ef3e792ad27","name":"WordPress  Relevanssi Premium Plugin  < 2.25 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi-premium\/vulnerability\/wordpress-relevanssi-premium-plugin-2-25-sensitive-data-exposure-vulnerability","description":"Update the WordPress Relevanssi Premium plugin to the latest available version (at least 2.25).\nAn unknown person discovered and reported this Sensitive Data Exposure vulnerability in WordPress Relevanssi Premium Plugin.  This vulnerability has been fixed in version 2.25.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":[]},{"uuid":"869f104de54b8000e950dd54cfeb30905e48cea3c8ac11a4ae593a6ff3005b50","name":"Relevanssi Premium [relevanssi-premium] < 2.25.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.25.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3214","name":"CVE-2024-3214","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3214","description":"[en] The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.","date":"2024-04-09"},{"id":"079321c0abbf5d10b5e8bc0d6560f83e6980760a","name":"WordPress  Relevanssi Premium Plugin    <= 2.25.1 is vulnerable to CSV Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi-premium\/vulnerability\/wordpress-relevanssi-premium-plugin-2-25-1-unauthenticated-second-order-csv-injection-vulnerability","description":"Update the WordPress Relevanssi Premium plugin to the latest available version (at least 2.25.2).\nThura Moe Myint (mgthuramoemyint) discovered and reported this CSV Injection vulnerability in WordPress Relevanssi Premium Plugin. This could allow a malicious actor to craft malicious formulas to then exploit vulnerabilities in the spreadsheet software or to execute commands to gain access to the victim';s PC. This vulnerability has been fixed in version 2.25.2.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-1236","name":"Improper Neutralization of Formula Elements in a CSV File","description":"The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"6192f19a7d23d5b294327cc60fbac580b3a9af45f3e21f9d459737846615de7a","name":"Relevanssi Premium [relevanssi-premium] < 2.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2318f92b-3502-450f-a728-00c0eb13f804","name":"Relevanssi Pro &lt; 2.25 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/wpscan.com\/vulnerability\/2318f92b-3502-450f-a728-00c0eb13f804","description":"The plugin is vulnerable to Sensitive Information Exposure, allowing unauthenticated attackers to extract sensitive user or configuration data.","date":null}],"impact":[]},{"uuid":"70b3bddeffd20bf70b834e3bdc3be65a9e115af0bff07f3df1bbb832628ef674","name":"Relevanssi Premium [relevanssi-premium] < 2.27.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.27.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-4396","name":"Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-4396","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries to already existing queries that can be used to extract sensitive information from the database.","date":"0000-00-00"},{"id":"c6896adbc94c5f5df500a2d503deab94a3dac38c","name":"WordPress Relevanssi Premium Plugin <= 2.27.4 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi-premium\/vulnerability\/wordpress-relevanssi-premium-plugin-2-27-4-unauthenticated-sql-injection","description":"<p>WordPress Relevanssi Premium Plugin <= 2.27.4 is vulnerable to SQL Injection<\/p><p>Software: Relevanssi Premium<\/p><p>Fixed in version 2.27.5 <\/p><p>Affected Version <= 2.27.4<\/p><p>CVE: CVE-2025-4396<\/p>","date":"2025-05-12"},{"id":"ab0415734dd586d58420364c6dabccbe8310ad63","name":"Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-4244-free-and-2274-premium-unauthenticated-sql-injection","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries to already existing queries that can be used to extract sensitive information from the database.","date":"2025-05-12"},{"id":"EUVD-2025-14360","name":"EUVD-2025-14360","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-14360","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.4 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries to already existing queries that can be used to extract sensitive information from the database.","date":"2025-05-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"025b6dd5a3a43f0b44699d8f13407f246335422ae731cd2bb7890fa1d33784ba","name":"Relevanssi Premium [relevanssi-premium] < 2.27.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.27.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-5016","name":"Relevanssi <= 4.24.5 (Free) and <= 2.27.6 (Premium) - Unauthenticated Stored Cross-Site Scripting via Excerpt Highlights","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-5016","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"3e4f966663aad6bf89d3fd7a803df9e0dc01cd0d","name":"Relevanssi <= 4.24.5 (Free) and <= 2.27.6 (Premium) - Unauthenticated Stored Cross-Site Scripting via Excerpt Highlights","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-4245-free-and-2276-premium-unauthenticated-stored-cross-site-scripting-via-excerpt-highlights","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-05-30"},{"id":"EUVD-2025-16540","name":"EUVD-2025-16540","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-16540","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-05-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.7","severity":"m","exploitable":"1.6","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.7","severity":"medium","av":"network","ac":"high","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.6","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.002"}},{"uuid":"3e2acc27b7adcee08116b62cc72b1d1a9df3c431574d168217fc45dbba753b66","name":"Relevanssi Premium [relevanssi-premium] < 2.30.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.30.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15941","name":"CVE-2026-15941","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15941","description":"[en] The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database.","date":"2026-08-05"},{"id":"7c211320a1a47af65e1c5b88abff349e9d9cc502","name":"Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/4f96b87a-1405-4cf6-b903-ad0c7c8e2826","description":"The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database.","date":"2026-08-04"},{"id":"83e4e34f1f2d832b6aabdb65d2696611ab9b27c5","name":"Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-4271-and-relevanssi-premium-2302-authenticated-contributor-sql-injection","description":"","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1785910731"}