Sceawere

Vulnerability Detail

CVE-2026-66659UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tablesome Table Blind SQL Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
3h ago
Vendor
Essekia
Product
Tablesome Table
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-08-12T06:22:09.420Z",
  "pubdate": "2026-08-12T06:22:09.420Z",
  "executiveSummary": "An Improper Neutralization of Special Elements used in an SQL Command vulnerability, commonly known as SQL Injection, has been identified in the Essekia Tablesome Table product. This security flaw enables attackers to execute Blind SQL Injection attacks against the underlying database management system. The vulnerability impacts the Tablesome Table plugin across versions ranging from n/a through 1.2.9. Successful exploitation of this vulnerability allows unauthorized threat actors to infer database contents and manipulate database queries through sophisticated payload delivery. The risk implications include potential unauthorized data extraction, compromise of database integrity, and possible underlying system exposure, depending on database user privileges. The attack capabilities require malicious manipulation of input parameters handled by the vulnerable component without proper sanitization or parameterized querying. Remediation is dependent on vendor-supplied patches, and no additional speculative exploitation requirements are noted beyond standard network access to the affected web application.",
  "technicalDetails": "The root cause of this vulnerability lies in the insecure handling and improper neutralization of user-supplied input before incorporating it directly into dynamic SQL queries executed by the application database layer. Specifically, the Tablesome Table product fails to adequately sanitize or parameterize input parameters within its database interaction logic, violating secure coding standards for database abstraction.\nThe affected component is the query generation and handling mechanism within Tablesome Table, impacting all software versions from n/a through 1.2.9. Network exposure is present via the web application interface hosting the vulnerable plugin, allowing remote entities to interact with the endpoints processing the unsanitized parameters.\nAuthentication and privilege requirements depend on the specific endpoint implementation exposed by the plugin, but typically remote attackers can target these interfaces directly via HTTP requests. The payload behavior involves injecting malicious SQL syntax, such as conditional statements or time-based delays, designed to evaluate boolean conditions against the database state.\nThe step-by-step attack flow proceeds as follows: First, the attacker identifies an input vector or parameter processed by the Tablesome Table component that interacts with the backend database without proper input validation. Second, the attacker crafts a malicious Blind SQL Injection payload containing SQL logical constructs or sleep functions. Third, the attacker submits this payload via the exposed application interface. Fourth, the vulnerable component concatenates or interpolates the malicious input directly into the SQL statement executed by the database engine. Fifth, because the application does not return direct database error messages or query results, the attacker observes indirect indicators such as HTTP response time differentials or boolean application state changes. Finally, through repeated iterative requests, the attacker extracts sensitive data character by character or maps the database schema, achieving post-exploitation impact characterized by unauthorized data disclosure and potential compromise of confidentiality."
}
CVE-2026-66659: Tablesome Table Blind SQL Injection (CRITICAL Severity, CVSS: 9.3) - Sceawere