CVE-2026-2395
Xpoda Türkiye Informatics Technology Inc.'s No Code Platform is vulnerable to SQL injection in versions 4.1.3 through 4.1.3.x. An attacker can execute arbitrary SQL commands, potentially compromising data and system integrity. The vulnerability is critical due to its ease of exploitation and severe impact.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Xpoda Türkiye Informatics Technology Inc. No Code Platform, versions 4.1.3 up to but not including 4.1.4.
Real-world impact
An attacker could run arbitrary SQL commands, reading, modifying, or deleting data, and potentially taking full control of the affected system.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited over the network without authentication, giving an attacker full control over confidentiality, integrity, and availability.
What to do about it
- 01Verify the current platform version.
- 02Upgrade the No Code Platform to version 4.1.4 or later.
- 03Restart the platform to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 22, 2026 · 10d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.