⤷ Title: From Second-Order SQLi to Full RCE: Breaking Through Filters in a Multi-Tenant Export Engine
════════════════════════
𐀪 Author: Omar Elshopky (3l5h0pky)
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 23:02:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_development #cybersecurity #sql_injection #postgresql
════════════════════════
𐀪 Author: Omar Elshopky (3l5h0pky)
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 23:02:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_development #cybersecurity #sql_injection #postgresql
Medium
From Second-Order SQLi to Full RCE: Breaking Through Filters in a Multi-Tenant Export Engine
Turning a constrained second-order SQL injection into full RCE by bypassing filters using PostgreSQL tricks and payload reconstruction.
⤷ Title: TryHackMe — Poster
════════════════════════
𐀪 Author: Kira @ hKiSec
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 00:07:34 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf_writeup #cybersecurity #postgresql #ctf
════════════════════════
𐀪 Author: Kira @ hKiSec
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 00:07:34 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf_writeup #cybersecurity #postgresql #ctf
Medium
TryHackMe — Poster
A Beginner’s Challenge from Exploiting PostgreSQL Weaknesses to Root Privileges
⤷ Title: Total Database Collapse: Inside the ElectricSQL CVSS 10.0 SQL Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 14:06:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40906 #CVSS 10 #cyber attack #database security #ElectricSQL #infosec #Multi_tenancy #Patch Alert #PostgreSQL #sql injection #sqli
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 14:06:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40906 #CVSS 10 #cyber attack #database security #ElectricSQL #infosec #Multi_tenancy #Patch Alert #PostgreSQL #sql injection #sqli
Daily CyberSecurity
Total Database Collapse: Inside the ElectricSQL CVSS 10.0 SQL Injection
ElectricSQL reveals a critical 10.0 CVSS SQL injection (CVE-2026-40906). Attackers can hijack PostgreSQL and bypass tenant isolation. Patch to v1.5.0 now.
⤷ Title: Database Indexing, B-Trees, and Query Optimization (2026)
════════════════════════
𐀪 Author: Kaushikking
════════════════════════
ⴵ Time: Mon, 27 Apr 2026 08:11:45 GMT
════════════════════════
⌗ Tags: #database #sql_injection #b_tree #sql #postgresql
════════════════════════
𐀪 Author: Kaushikking
════════════════════════
ⴵ Time: Mon, 27 Apr 2026 08:11:45 GMT
════════════════════════
⌗ Tags: #database #sql_injection #b_tree #sql #postgresql
Medium
Database Indexing, B-Trees, and Query Optimization (2026)
A startup CTO once hired me because their primary dashboard was taking 14 seconds to load. He told me, “I don’t understand, I added an…
⤷ Title: Critical LiteLLM SQL Injection (CVE-2026-42208) Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 01:53:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_42208 #cybersecurity #Data Breach #Exploit #infosec #LiteLLM #Patch Alert #PostgreSQL #sql injection #Sysdig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 01:53:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_42208 #cybersecurity #Data Breach #Exploit #infosec #LiteLLM #Patch Alert #PostgreSQL #sql injection #Sysdig
Daily CyberSecurity
Critical LiteLLM SQL Injection (CVE-2026-42208) Exploited in the Wild
LiteLLM CVE-2026-42208 is under active exploitation. Attackers are using SQL injection to steal AI credentials. Patch to v1.83.7 and rotate keys immediately.
⤷ Title: Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 04 May 2026 15:08:40 +0000
════════════════════════
⌗ Tags: #Security #Cybersecurity #Google #MariaDB #PostgreSQL #Technology #Vulnerability #Wiz #ZeroDay.Cloud
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 04 May 2026 15:08:40 +0000
════════════════════════
⌗ Tags: #Security #Cybersecurity #Google #MariaDB #PostgreSQL #Technology #Vulnerability #Wiz #ZeroDay.Cloud
Hackread
Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities
Researchers revealed 20-year-old PostgreSQL flaws at Wiz ZeroDay.Cloud event, exposing critical bugs in pgcrypto and prompting urgent patches for database security.
⤷ Title: Critical 9.4 CVSS pgAdmin 4 Flaws Enable Full OS Command Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 15 May 2026 01:20:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2026_7813 #Cyber Security #database security #infosec #Patch Alert #pgAdmin 4 #pgAdmin 9.15 #PostgreSQL #rce #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 15 May 2026 01:20:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2026_7813 #Cyber Security #database security #infosec #Patch Alert #pgAdmin 4 #pgAdmin 9.15 #PostgreSQL #rce #sql injection
Daily CyberSecurity
Critical 9.4 CVSS pgAdmin 4 Flaws Enable Full OS Command Execution
pgAdmin 4 v9.15 fixes a 9.4 CVSS auth bypass and multiple RCE flaws. Attackers can execute OS commands via SQL tools. Upgrade your pgAdmin server now!
⤷ Title: Kubernetes Alert: 9.4 Severity RCE in CloudNativePG Enables PostgreSQL Superuser Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 15 May 2026 01:01:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cloud_native #CloudNativePG #CVE_2026_44477 #database security #infosec #Kubernetes Security #Patch Alert #PostgreSQL #privilege escalation #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 15 May 2026 01:01:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cloud_native #CloudNativePG #CVE_2026_44477 #database security #infosec #Kubernetes Security #Patch Alert #PostgreSQL #privilege escalation #rce
Daily CyberSecurity
Kubernetes Alert: 9.4 Severity RCE in CloudNativePG Enables PostgreSQL Superuser Takeover
CVE-2026-44477 in CloudNativePG allows low-privilege users to gain root-level RCE via metrics exporters. Update to version 1.29.1 or 1.28.3 now!
⤷ Title: Massive PostgreSQL Update: 11 Vulnerabilities Patched as Version 14 Hits End-of-Life Warning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 02:12:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Execution #CVE_2026_6477 #CVE_2026_6637 #database security #DevOps #infosec #Patch Alert #Postgres Update #PostgreSQL #sql injection #SysAdmin
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 02:12:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Execution #CVE_2026_6477 #CVE_2026_6637 #database security #DevOps #infosec #Patch Alert #Postgres Update #PostgreSQL #sql injection #SysAdmin
Daily CyberSecurity
Massive PostgreSQL Update: 11 Vulnerabilities Patched as Version 14 Hits End-of-Life Warning
PostgreSQL releases updates for versions 14-18 fixing 11 vulnerabilities (CVSS 8.8). Plus, critical End-of-Life deadline issued for Postgres 14.
⤷ Title: PoC Exploit Publicly Disclosed: 20-Year-Old PostgreSQL pgcrypto Flaw (CVE-2026-2005) Grants Full Superuser RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:51:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_2005 #database security #Heap Buffer Overflow #infosec #Patch Alert #pgcrypto #PoC Exploit #PostgreSQL #Public Disclosure #rce #Superuser Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:51:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_2005 #database security #Heap Buffer Overflow #infosec #Patch Alert #pgcrypto #PoC Exploit #PostgreSQL #Public Disclosure #rce #Superuser Escalation
Daily CyberSecurity
PoC Exploit Publicly Disclosed: 20-Year-Old PostgreSQL pgcrypto Flaw (CVE-2026-2005) Grants Full Superuser RCE
Technical details and GitHub PoC exploits disclosed for PostgreSQL pgcrypto CVE-2026-2005. Low-privilege users can seize root superuser RCE. Patch now!
⤷ Title: Critical 9.8 CVSS: Severe SQL Injection Flaw Exposed in Marten .NET Document Store Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:04:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET Security #ACID Document Database #CVE_2026_45288 #Cyber Security #Full_Text Search #infosec #Marten .NET #Patch Alert #PostgreSQL #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:04:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET Security #ACID Document Database #CVE_2026_45288 #Cyber Security #Full_Text Search #infosec #Marten .NET #Patch Alert #PostgreSQL #sql injection
Daily CyberSecurity
Critical 9.8 CVSS: Severe SQL Injection Flaw Exposed in Marten .NET Document Store Engine
Marten .NET library suffers a critical 9.8 CVSS SQL injection flaw (CVE-2026-45288). Learn how to block the exploit and patch your databases now!
⤷ Title: Drupal Database API Flaw (CVE-2026-9082) Exposes PostgreSQL Sites to Unauthenticated SQLi
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 01:35:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_9082 #Cyber Security #Database Abstraction API #Drupal Core #infosec #PostgreSQL Security #SA_CORE_2026_004 #sql injection #Symfony Patch #Twig Template #unauthenticated RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 01:35:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_9082 #Cyber Security #Database Abstraction API #Drupal Core #infosec #PostgreSQL Security #SA_CORE_2026_004 #sql injection #Symfony Patch #Twig Template #unauthenticated RCE
Daily CyberSecurity
Exploited in the Wild: Critical Drupal SQL Injection (CVE-2026-9082) Grants Attacker Root Access
Urgent: Drupal releases patches for highly critical SQLi flaw CVE-2026-9082. Unauthenticated attackers can exploit PostgreSQL backends for full remote RCE.
⤷ Title: Drupal SQL Injection Exploit: Critical Flaw Exploited in the Wild with Public PoC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 07:54:18 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2026_9082 #Drupal Core #PostgreSQL Superuser #Remote Code Execution #sql injection #threat analysis
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 07:54:18 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2026_9082 #Drupal Core #PostgreSQL Superuser #Remote Code Execution #sql injection #threat analysis
Daily CyberSecurity
Drupal SQL Injection Exploit: Critical Flaw Exploited in the Wild with Public PoC
A critical Drupal SQL injection exploit is active in the wild. Read the analysis of this flaw now that the wild exploit PoC is fully public.
⤷ Title: From Default Credentials to Operating System Access: Exploiting PostgreSQL in Metasploitable 2
════════════════════════
𐀪 Author: VISHAL PRAJAPATI
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:06:04 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #linux #postgresql #cybersecurity
════════════════════════
𐀪 Author: VISHAL PRAJAPATI
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:06:04 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #linux #postgresql #cybersecurity
Medium
From Default Credentials to Operating System Access: Exploiting PostgreSQL in Metasploitable 2
When people think about penetration testing, they often imagine sophisticated exploits and advanced malware. In reality, many compromises…
⤷ Title: Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 00:30:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12045 #CVE_2026_12046 #CVE_2026_12048 #pgAdmin #pgAdmin 4 vulnerabilities #PostgreSQL #Prompt injection #Stored XSS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 00:30:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12045 #CVE_2026_12046 #CVE_2026_12048 #pgAdmin #pgAdmin 4 vulnerabilities #PostgreSQL #Prompt injection #Stored XSS
Daily CyberSecurity
Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi
Three critical pgAdmin 4 vulnerabilities (CVE-2026-12046, CVE-2026-12048, CVE-2026-12045) risk XSS and RCE. Update to pgAdmin 4 9.16 now.
⤷ Title: The Code Was Fine. The Access Model Was Not.
════════════════════════
𐀪 Author: Shiki65536@TechRoamer
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 09:05:37 GMT
════════════════════════
⌗ Tags: #application_security #postgresql #database_security #backend_development #supabase
════════════════════════
𐀪 Author: Shiki65536@TechRoamer
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 09:05:37 GMT
════════════════════════
⌗ Tags: #application_security #postgresql #database_security #backend_development #supabase
Medium
The Code Was Fine. The Access Model Was Not.
This week, Supabase flagged several backend tables with: RLS Disabled in Public.
⤷ Title: PHP SQL Injection Flaw CVE-2026-17543 Patched in Latest Release
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 01:58:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BCMath #CVE_2026_17543 #php #PHP Security #PostgreSQL #sql injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 01:58:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BCMath #CVE_2026_17543 #php #PHP Security #PostgreSQL #sql injection
Daily CyberSecurity
PHP SQL Injection Flaw CVE-2026-17543 Patched in Latest Release
TL;DR The PHP project fixed three flaws in its latest releases. The headline bug is a PHP SQL injection flaw, CVE-2026-17543, in the PostgreSQL extension. Two memory-safety bugs round out the set.…
⤷ Title: Building Multi-Tenant Isolation in Supabase — and Learning to Break It
════════════════════════
𐀪 Author: Joefrancis
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 13:56:46 GMT
════════════════════════
⌗ Tags: #postgresql #semgrep #full_stack_developer #application_security #multitenancy
════════════════════════
𐀪 Author: Joefrancis
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 13:56:46 GMT
════════════════════════
⌗ Tags: #postgresql #semgrep #full_stack_developer #application_security #multitenancy
Medium
Building Multi-Tenant Isolation in Supabase — and Learning to Break It
Building secure multi-tenant systems — and verifying them through application security testing.
⤷ Title: Hijacking the Backend: A Custom SafeLine WAF-to-Splunk Pipeline
════════════════════════
𐀪 Author: aarushi.jha
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 17:33:26 GMT
════════════════════════
⌗ Tags: #postgresql #splunk #cybersecurity #web_application_firewall #infosec
════════════════════════
𐀪 Author: aarushi.jha
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 17:33:26 GMT
════════════════════════
⌗ Tags: #postgresql #splunk #cybersecurity #web_application_firewall #infosec
Medium
Hijacking the Backend: A Custom SafeLine WAF-to-Splunk Pipeline
Setting up SafeLine WAF was the easy part. You spin up the Docker containers, route your traffic, and watch it start eating malicious…
⤷ Title: pgAdmin 4 RCE Flaw Leads Three Critical Fixes in Version 9.17
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 01:02:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Assistant Security #Credential Theft #CVE_2026_17566 #Database Tools #pgAdmin #PostgreSQL #Remote Code Execution #sql injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 01:02:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Assistant Security #Credential Theft #CVE_2026_17566 #Database Tools #pgAdmin #PostgreSQL #Remote Code Execution #sql injection
Daily CyberSecurity
pgAdmin 4 RCE Flaw Leads Three Critical Fixes in Version 9.17
TL;DR: The pgAdmin Development Team patched a pgAdmin 4 RCE flaw tracked as CVE-2026-17566, rated CVSS 9.4. Version 9.17 also fixes a credential-cloning bug and an AI Assistant bypass, alongside f…