{"id":"CVE-2026-58492","summary":"grav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name Interpolation","details":"grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a raw SQL query string without sanitization, escaping, quoting, or whitelisting, allowing attacker-controlled table names passed by consuming plugin or developer code to execute arbitrary SQL against the configured database. This issue is fixed in version 1.2.0.","aliases":["GHSA-8jxg-4pw9-xcwf"],"modified":"2026-07-15T01:48:56.493800909Z","published":"2026-07-10T16:22:37.052Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58492.json"},"references":[{"type":"WEB","url":"https://github.com/getgrav/grav-plugin-database/releases/tag/1.2.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58492.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-8jxg-4pw9-xcwf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58492"},{"type":"FIX","url":"https://github.com/getgrav/grav-plugin-database/commit/f6d058785c9e23df7efc5ea7556f8746fef286df"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getgrav/grav-plugin-database","events":[{"introduced":"0"},{"fixed":"f6d058785c9e23df7efc5ea7556f8746fef286df"},{"fixed":"4fe933eafa564a7411777ba2a47cfacf89d200df"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.2.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.1.2","1.1.1","1.1.0","1.0.2","1.0.1","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58492.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}