Junglewise Threat Intelligence

CVE-2026-2395: Xpoda No Code Platform SQL injection

CVE-2026-2395 · Severity: critical · CVSS 9.8 · Published 2026-07-22

Executive brief

Xpoda No Code Platform, a tool used by businesses to build applications without manual coding, contains a critical security flaw. This vulnerability allows an outside attacker to manipulate the platform's database commands over the internet. If exploited, an attacker could steal sensitive customer data, modify business records, or disrupt the platform's availability entirely.

Technical details

A SQL injection vulnerability (CWE-89) exists in the Xpoda No Code Platform due to improper neutralization of special elements used in SQL commands. The flaw is exploitable over the network without authentication, requiring low attack complexity and no user interaction. An attacker can leverage this to gain full access to the underlying database, potentially leading to complete loss of confidentiality, integrity, and availability. The vulnerability affects versions 4.3.1.0 through 20260722; notably, the vendor has not responded to disclosure attempts as of the publication date.

Affected products

  • Xpoda Türkiye Informatics Technology Inc. No Code Platform 4.3.1.0 through 20260722

Timeline

  • 2026-07-22: advisory: Initial disclosure by TR-CERT and NVD
  • 2026-07-22: disclosed: Vendor was contacted early but did not respond

References