An unauthenticated JCR-SQL2 injection exists in the Smart Content category filter of the 2.x content query builder.
Category IDs supplied through the public ?categories= query parameter are only trimmed and are then concatenated directly into a JCR-SQL2 WHERE clause, without the numeric validation that the equivalent tag filter already performs. Any public page that renders a Smart Content element with category filtering enabled evaluates this parameter, so no authentication or special configuration beyond a category-filtered content block is required.
An anonymous visitor can therefore:
Because the sink is a JCR-SQL2 query, the impact is limited to reading and enumerating content-repository nodes and to error/denial-of-service conditions; it cannot be used to modify data through this path.
Fixed in 2.6.25 and 3.0.8. Category, tag, and audience-target-group IDs are now cast to integers before they are used in the JCR-SQL2 query, so no attacker-controlled characters can reach the query.
If you cannot upgrade immediately:
WHERE clause in the content Smart Content query builder.{
"cwe_ids": [
"CWE-89"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-23T18:21:22Z",
"nvd_published_at": null,
"severity": "MODERATE"
}