CVE-2026-5955
Last modified
CVE-2026-5955 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Inrove Software and Internet Services | BiEticaret | < v3.3.57 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-5955?
How severe is CVE-2026-5955?
How do I fix CVE-2026-5955?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59544Unauthenticated PHP Object Injection in Thrive Quiz Builder …9.8
- CVE-2026-59545Unauthenticated Broken Authentication in miniOrange Discord …8.1
- CVE-2026-59546Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.…7.4
- CVE-2026-59547Unauthenticated Broken Access Control in Payment Gateway for…7.5
- CVE-2026-59548Unauthenticated Sensitive Data Exposure in Byteflows Travel …7.5
- CVE-2026-59549Unauthenticated SQL Injection in rtMedia for WordPress, Budd…9.3
- CVE-2026-59550Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 ve…9.3
- CVE-2026-59551Subscriber SQL Injection in rtMedia for WordPress, BuddyPres…8.5
- CVE-2026-59552Unauthenticated Server Side Request Forgery (SSRF) in 3D Fli…7.2
- CVE-2026-59553Unauthenticated Cross Site Scripting (XSS) in Product Feed M…7.1
- CVE-2026-59554Unauthenticated Broken Authentication in Ziina <= 1.2.21 ver…7.5
- CVE-2026-59555Unauthenticated Arbitrary File Deletion in Participants Data…10
Are you affected by CVE-2026-5955?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
