Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 11 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose records by the meta field.This issue affects corteza: 2024.9.8. | |
| Title | Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping | |
| First Time appeared |
Cortezaproject
Cortezaproject corteza |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:cortezaproject:corteza:2024.9.8:*:linux:*:*:*:*:* cpe:2.3:a:cortezaproject:corteza:2024.9.8:*:macos:*:*:*:*:* cpe:2.3:a:cortezaproject:corteza:2024.9.8:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Cortezaproject
Cortezaproject corteza |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-05-11T19:26:53.093Z
Reserved: 2026-04-10T16:08:10.755Z
Link: CVE-2026-6093
No data.
Status : Deferred
Published: 2026-05-11T16:17:36.800
Modified: 2026-05-12T18:56:44.480
Link: CVE-2026-6093
No data.
OpenCVE Enrichment
Updated: 2026-05-12T09:23:12Z