CVE-2026-2094Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-02-10); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-10: 4Mentions · 2026-02-15: 1Technical Details · 2026-02-10: 3Technical Details · 2026-02-15: 102-1002-15
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-104
Disclosure3General1
2026-02-151
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2094 (CVSS:8.7, HIGH) is Awaiting Analysis. Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbi..https://nvd.nist.gov/vuln/detail/CVE-2026-2094 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-2094 is a SQL Injection vulnerability in Docpedia (Flowring) rated CVSS 8.7, and is currently awaiting analysis.

    0000035
    171 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2094: HIGH] Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.#cve,CVE-2026-2094,#cybersecurity https://cvefind.com/CVE-2026-2094

    Post summary

    The post discloses a high‑severity SQL injection flaw in Docpedia that allows authenticated remote attackers to manipulate database contents, but does not mention any PoC, exploit code, active attacks, or remediation steps.

    0000055
    583 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-2094 - Flowring - Docpedia - https://www.redpacketsecurity.com/cve-alert-cve-2026-2094-flowring-docpedia/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2094 #flowring #docpedia

    Post summary

    The message announces a CVE alert and provides a link to a website, but offers no further technical details, PoC information, or exploitation evidence.

    0000067
    3.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2094 SQL Injection in Docpedia by Flowring Enables Unauthorized Database Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2094

    Post summary

    The text reports the discovery of a SQL Injection vulnerability (CVE‑2026‑2094) in Flowring's Docpedia, enabling unauthorized database manipulation, without mentioning PoC, exploit code, or patches.

    0000051
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-2094 - High Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. https://www.thehackerwire.com/vulnerability/CVE-2026-2094/ https://t.co/vG1HW3pvB8

    Post summary

    The text announces CVE‑2026‑2094, a SQL Injection flaw in Docpedia that permits authenticated remote attackers to execute arbitrary SQL commands, but offers no PoC, exploit code, or evidence of active exploitation.

    0000057
    112 followersView on X

Explore more