THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m7jc-g4rc-jmvh (medium) — Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax

[GHSA] GHSA-m7jc-g4rc-jmvh (medium) — Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax

highgithub_advisoriesPublished 2026-08-12

GHSA-m7jc-g4rc-jmvh Severity: medium CVE: CVE-2026-32593

Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax

## Impact

The Backend Filter widget (`Backend\Widgets\Filter`) is vulnerable to SQL injection through the `numberrange` scope type when the scope is configured with a `conditions` key. An authenticated backend user with access to a list view containing a

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m7jc-g4rc-jmvh