Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection.

This issue affects No Code Platform: from 4.1.3 before 4.1.4.
Published: 2026-07-22
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of special elements used in an SQL command allows an attacker to inject arbitrary SQL code, potentially compromising the confidentiality and integrity of the database. This flaw is scored 9.8 on the CVSS scale, indicating a critical level of impact.

Affected Systems

Xpoda Türkiye Informatics Technology Inc. No Code Platform, versions starting at 4.1.3 up to but not including 4.1.4, are affected.

Risk and Exploitability

The CVSS score of 9.8 places the vulnerability in the critical range. The EPSS score of <1% indicates a very low likelihood of exploitation. The flaw is not listed in CISA's KEV catalog. It is inferred that an attacker could exploit the flaw via the platform’s web interface by submitting malicious input that is incorporated into SQL statements, provided that input sanitization is insufficient or nonexistent.

Generated by OpenCVE AI on August 3, 2026 at 23:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the No Code Platform to a version newer than 4.1.3 (for example, 4.1.4 or later), which removes the flaw according to the version range data.
  • Implement input validation or sanitization on all data used in SQL queries to mitigate injection attacks based on CWE-89.
  • Restrict access to the web interface to trusted users or via a secure VPN to reduce the attack surface for potential SQL injection attempts.
  • Deploy a web application firewall or equivalent rule set to detect and block malformed SQL payloads.

Generated by OpenCVE AI on August 3, 2026 at 23:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.3.1.0 through 20260722. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.1.3 before 4.1.4.

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Xpoda Turkiye Information Technology
Xpoda Turkiye Information Technology no Code Platform
Vendors & Products Xpoda Turkiye Information Technology
Xpoda Turkiye Information Technology no Code Platform

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.3.1.0 through 20260722. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title SQLi in Xpoda Türkiye Informatics Technology's No Code Platform
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Xpoda Turkiye Information Technology No Code Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-30T11:25:33.239Z

Reserved: 2026-02-12T12:48:07.234Z

Link: CVE-2026-2395

cve-icon Vulnrichment

Updated: 2026-07-22T18:58:44.534Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T15:16:54.193

Modified: 2026-07-30T12:18:02.457

Link: CVE-2026-2395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')