Vulnerabilities > Puzzle

DATE CVE VULNERABILITY TITLE RISK
2023-02-20 CVE-2023-26092 Expression Language Injection vulnerability in Puzzle Liima
Liima before 1.17.28 allows server-side template injection.
network
low complexity
puzzle CWE-917
critical
9.8
2023-02-20 CVE-2023-26093 SQL Injection vulnerability in Puzzle Liima
Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.
network
low complexity
puzzle CWE-89
critical
9.8