CWE-943

CWE-943 · 5 records · 5 with a public proof-of-concept

Records the NVD classes under CWE-943, highest CVSS first.

  1. HIGH 7.5CVE-2026-100631public PoC

    Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields befor…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.1CVE-2026-96744public PoC

    Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than as a literal value. An…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.7CVE-2026-48121public PoC

    @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) from conf…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.5CVE-2026-91133public PoC

    Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated users could supply unescaped SQL LIKE metacharacters to upload-resolution patterns, causing wildcard input to select unrelated upload records in…

    AI risk analysis on Exploit-DB.ai →

  5. LOW 2.7CVE-2026-97228public PoC

    Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/export_manager.py`), whereby the `export_id` value — an unvalidated MCP tool argument reaching the funct…

    AI risk analysis on Exploit-DB.ai →