Skip to content
SQL Injection Vulnerabilities Discovered in Kolay and DATABASE Software

SQL Injection Vulnerabilities Discovered in Kolay and DATABASE Software

First seen 20 Feb 2026, 23:17 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

Two SQL injection vulnerabilities have been identified in software from Kolay Software Inc. and DATABASE Software Training Consulting Ltd. The vulnerabilities, CVE-2025-10970 and CVE-2025-9953, allow unauthenticated attackers to execute SQL injection attacks, potentially bypassing authorization controls. Both vendors were contacted but did not respond to the disclosures.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

Timeline

2026-02-19
CVE-2025-9953 published
2026-02-19
CVE-2026-25755 published
2026-02-20
CVE-2025-10970 published

More articles in this cluster (2)

Following this threat?

Track CVE-2025-10970 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed