Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p32q-v29x-wq9r | Focalboard doesn't sanitize category IDs before incorporating them into dynamic SQL statements |
| Link | Providers |
|---|---|
| https://github.com/mattermost-community/focalboard |
|
Tue, 28 Apr 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mattermost:focalboard:8.0.0:*:*:*:*:*:*:* |
Fri, 03 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost focalboard |
|
| Vendors & Products |
Mattermost
Mattermost focalboard |
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to sanitize category IDs before incorporating them into dynamic SQL statements when reordering categories. An attacker can inject a malicious SQL payload into the category id field, which is stored in the database and later executed unsanitized when the category reorder API processes the stored value. This Second-Order SQL Injection (Time-Based Blind) allows an authenticated attacker to exfiltrate sensitive data including password hashes of other users. NOTE: Focalboard as a standalone product is not maintained and no fix will be issued. | |
| Title | Focalboard Second-Order SQL Injection in category reorder endpoint allows data exfiltration (unsupported product, no fix) | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-04-03T14:57:00.729Z
Reserved: 2026-04-03T13:10:59.186Z
Link: CVE-2026-25773
Updated: 2026-04-03T14:56:50.635Z
Status : Analyzed
Published: 2026-04-03T14:16:29.127
Modified: 2026-04-28T00:19:15.587
Link: CVE-2026-25773
No data.
OpenCVE Enrichment
Updated: 2026-04-03T21:16:35Z
Github GHSA