← All CVEs

CVE-2026-11561

critical · 9.8

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6.

9.8
CVSS
0.4%
EPSS (exploit prob.)
38th
EPSS percentile
2026-06-11
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-917

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-11561