All verified exploits

CVE-2026-31840 SQL Injection via Dot-Notation Sort Parameter (PostgreSQL)

Pentest critical Parse Server Added cve-verified-cve-2026-31840

Detects Parse Server instances using PostgreSQL where the sort/order query parameter accepts dot-notation field names with unescaped single quotes in sub-field values. An attacker with the Application ID and REST API key (typically exposed in client-side code) can inject arbitrary SQL via the order parameter, enabling full database access.

Is your app exploitable through CVE-2026-31840?

Scan your domain free