<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 19:47:14 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-8206</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-8206</link>
      <description>EUVD-2026-8206</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-8206</guid>
    </item>
    <item>
      <title>fkie_cve-2023-25330</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-25330</link>
      <description>&lt;p&gt;A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer. NOTE: the vendor&amp;#39;s position is that this can only occur in a misconfigured application; the documentation discusses how to develop applications that avoid SQL injection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer. NOTE: the vendor&amp;#39;s position is that this can only occur in a misconfigured application; the documentation discusses how to develop applications that avoid SQL injection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-25330</guid>
    </item>
    <item>
      <title>GHSA-32qq-m9fh-f74w — MyBatis-Plus vulnerable to SQL injection via TenantPlugin</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-32qq-m9fh-f74w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.baomidou:mybatis-plus&lt;/p&gt;
&lt;p&gt;MyBatis-Plus below 3.5.3.1 is vulnerable to SQL injection via the tenant ID value. This may allow remote attackers to execute arbitrary SQL commands.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.baomidou:mybatis-plus&lt;/p&gt;
&lt;p&gt;MyBatis-Plus below 3.5.3.1 is vulnerable to SQL injection via the tenant ID value. This may allow remote attackers to execute arbitrary SQL commands.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-32qq-m9fh-f74w</guid>
    </item>
    <item>
      <title>gsd-2023-25330</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-25330</link>
      <description>gsd-2023-25330</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-25330</guid>
    </item>
    <item>
      <title>OESA-2023-1996 — mybatis security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1996</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: mybatis&lt;/p&gt;
&lt;p&gt;The MyBatis data mapper framework makes it easier to use a relational database with object-oriented applications. MyBatis couples objects with stored procedures or SQL statements using a XML descriptor or annotations. Simplicity is the biggest advantage of the MyBatis data mapper over object relational mapping tools. To use the MyBatis data mapper, you rely on your own objects, XML, and SQL. There is little to learn that you don&amp;amp;apos;t already know. With the MyBatis data mapper, you have the full power of both SQL and stored procedures at your fingertips. The MyBatis project is developed and maintained by a team that includes the original creators of the &amp;amp;quot;iBATIS&amp;amp;quot; data mapper. The Apache project was retired and continued here.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer.(CVE-2023-25330)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: mybatis&lt;/p&gt;
&lt;p&gt;The MyBatis data mapper framework makes it easier to use a relational database with object-oriented applications. MyBatis couples objects with stored procedures or SQL statements using a XML descriptor or annotations. Simplicity is the biggest advantage of the MyBatis data mapper over object relational mapping tools. To use the MyBatis data mapper, you rely on your own objects, XML, and SQL. There is little to learn that you don&amp;amp;apos;t already know. With the MyBatis data mapper, you have the full power of both SQL and stored procedures at your fingertips. The MyBatis project is developed and maintained by a team that includes the original creators of the &amp;amp;quot;iBATIS&amp;amp;quot; data mapper. The Apache project was retired and continued here.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer.(CVE-2023-25330)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1996</guid>
    </item>
  </channel>
</rss>
