CVE-2026-58492

grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a raw SQL query string without sanitization, escaping, quoting, or whitelisting, allowing attacker-controlled table names passed by consuming plugin or developer code to execute arbitrary SQL against the configured database. This issue is fixed in version 1.2.0.
CVSS

No CVSS.

Configurations

No configuration.

History

10 Jul 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 17:17

Updated : 2026-07-10 17:35


NVD link : CVE-2026-58492

Mitre link : CVE-2026-58492

CVE.ORG link : CVE-2026-58492


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')