CVE-2026-2395EPSS p38.4%
CVE-2026-2395CVE-2026-2395
Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection.
This issue affects No Code Platform: from 4.1.3 before 4.1.4.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.47% probability of exploitation · percentile 38.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-30 |