Vulnerabilities > Kohanaframework > Kohana > 3.3.6
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-02-21 | CVE-2019-8979 | SQL Injection vulnerability in Kohanaframework Kohana Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled. | 9.8 |