CWE-943— Improper Neutralization of Special Elements in Data Query Logic
The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.— MITRE CWE catalog
110 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-943page 3 of 3
- CVE-2026-88027HIGHCVSS 7.1EG 7.12026-09-10
Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query condition…
- CVE-2026-88028MEDIUMCVSS 6.5EG 6.52026-09-10
Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather than …
- CVE-2026-88029HIGHCVSS 8.3EG 8.32026-09-10
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…
- CVE-2026-88030HIGHCVSS 8.3EG 8.32026-09-10
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…
- CVE-2026-88031HIGHCVSS 8.1EG 8.12026-09-10
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identif…
- CVE-2026-88033HIGHCVSS 8.3EG 8.32026-09-10
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…
- CVE-2026-88034HIGHCVSS 8.3EG 8.32026-09-10
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identi…
- CVE-2026-88036HIGHCVSS 8.3EG 8.32026-09-10
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifi…
- CVE-2026-91937HIGHCVSS 7.5EG 7.52026-09-15
Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to rea…
- CVE-2026-93760HIGHCVSS 8.2EG 8.22026-09-18
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way,…
Map vulnerabilities like CWE-943 to your infrastructure
EchelonGraph correlates every CVE — across CWE-943 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →