Vulnerability Database

311,378

Total vulnerabilities in the database

CVE-2023-26443

Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly encode single quotes for SQL FULLTEXT queries. No publicly available exploits are known.

  • Published: Aug 2, 2023
  • Updated: Nov 16, 2025
  • CVE: CVE-2023-26443
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.5
  • AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L

CWEs:

OWASP TOP 10: