rootpwn

critical · CVSS v3 9.8

CVE-2026-18782

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart…

Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.

Scores

Severity
critical
CVSS v2
10
CVSS v3
9.8
CVSS v4
—
EPSS
—

← All CVEs