go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Flowring|Docpedia - 2 Vulnerabilities

TVN ID TVN-202602001
CVE ID CVE-2026-2093, CVE-2026-2094
CVSS CVE-2026-2093:
7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2026-2094:
8.8 (High) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products Docpedia 3.0
Description CVE-2026-2093:
Docpedia has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

CVE-2026-2094:
Docpedia has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Solution Please install the patch DP4 HotFix_057.
Credit ChunHao Yang(CHTSecurity)
Public Date 2026-02-06
Top