GHSA-q57j-rwwx-7rwp

Suggest an improvement
Source
https://github.com/advisories/GHSA-q57j-rwwx-7rwp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-q57j-rwwx-7rwp/GHSA-q57j-rwwx-7rwp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q57j-rwwx-7rwp
Aliases
  • CVE-2026-42474
Published
2026-05-01T18:31:24Z
Modified
2026-05-07T17:11:25Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
MixPHP Framework has an SQL injection vulnerability via crafted `data` array
Details

SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted data array to the data function in BuildHelper.php.

Database specific
{
    "cwe_ids":  [
        "CWE-89"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-07T16:45:30Z",
    "nvd_published_at":  "2026-05-01T16:16:31Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / mix/mix

Package

Name
mix/mix
Purl
pkg:composer/mix/mix

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Last Affected
2.2.17

Affected versions

v2.*
v2.0.1-Beta2
v2.0.1-RC
v2.0.1-RC2
v2.0.1-RC5
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.1.0-beta
v2.1.0-RC
v2.1.0-RC2
v2.1.0
v2.1.1
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v2.1.9
v2.1.10
v2.1.11
v2.1.12
v2.1.15
v2.2.4
v2.2.5
v2.2.7
v2.2.9
v2.2.11
v2.2.12
v2.2.13
v2.2.14
v2.2.15
v2.2.16
v2.2.17

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-q57j-rwwx-7rwp/GHSA-q57j-rwwx-7rwp.json"