Threats Tagged 'cve-2026-2093'
View all threats tagged with 'cve-2026-2093'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-2093'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-2093 is a high-severity SQL Injection vulnerability in Flowring's Docpedia version 3.0. It allows unauthenticated remote attackers to inject arbitrary SQL commands, potentially exposing sensitive database contents without requiring any user interaction or privileges. The vulnerability stems from improper neutralization of special elements in SQL commands (CWE-89). Although no known exploits are currently reported in the wild, the ease of exploitation and the critical impact on confidentiality make this a significant threat. European organizations using Docpedia 3.0 are at risk of data breaches and unauthorized data disclosure. Immediate mitigation involves applying patches once available, implementing web application firewalls with SQLi detection, and auditing database query handling. Countries with higher adoption of Flowring Docpedia, especially those with critical infrastructure or sensitive data managed via this product, are more likely to be targeted. Given the CVSS 4. Join the discussion | CVE Database V5 | 02/10/2026, 06:45:34 UTC Added: 02/10/2026, 07:16:16 UTC |
Showing 1 to 1 of 1 result