Frequency
2
occurrences
First Seen
July 16, 2026
Last Seen
July 16, 2026
Related Threat Clusters
-
Critical SQL Injection Vulnerability in NocoBase (CVE-2026-52887)
CVE-2026-52887 is a critical SQL injection vulnerability affecting NocoBase, an AI-powered no-code/low-code platform. The flaw allows unauthenticated remote attackers to execute arbitrary SQL queries via the…
2 articles · Updated July 16, 2026
Recent Intelligence Reports
- CVE-2026-52887 AKAOMA CVE VULNERABILITIES / 12h NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements an — cve.akaoma.com · July 16, 2026
- CVE-2026-52887 - Exploits & Severity — Feedly · July 16, 2026