SQL Injection Vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform
CVE-2026-2395

9.8CRITICAL

What is CVE-2026-2395?

A vulnerability in the No Code Platform by Xpoda Türkiye allows for SQL injection attacks due to improper handling of special elements in SQL commands. This exposure can lead to unauthorized data access, data modification, and potential loss of confidentiality and integrity of sensitive information. The issue impacts versions from 4.3.1.0 up to and including 20260722. Despite early notifications regarding this severity, the vendor has not provided a response or mitigation steps.

Affected Version(s)

No Code Platform 4.3.1.0 <= 20260722

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Murat ERDEMİR
.