Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

Medinik Core: Unsecured Input Can Expose Sensitive Data

CVE-2025-69307
Summary

The Medinik Core software has a security flaw that makes it vulnerable to a type of attack that can extract sensitive information from a database. This could allow an attacker to access confidential data. To protect your system, update to a version of Medinik Core that is not affected by this issue.

Original title
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Medinik Core medinik-core allows Blind SQL Injection.This issue affects Medinik Co...
Original description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Medinik Core medinik-core allows Blind SQL Injection.This issue affects Medinik Core: from n/a through <= 1.3.6.
nvd CVSS3.1 9.3
Vulnerability type
CWE-89 SQL Injection
Published: 20 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026