CVE-2026-31917Patch

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through <= 1.16.10.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-13); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 103-1303-1403-15
Signal classification3 categories
Patch
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-131
Patch1
2026-03-141
Disclosure1
2026-03-151
General1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-31917 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP… https://www.cve.org/CVERecord?id=CVE-2026-31917

    Post summary

    The statement lists CVE‑2026‑31917, describes it as an SQL injection flaw in weDevs WP ERP, and links to the CVE record, without providing additional technical depth, PoC, exploit details, or patch information.

    00000159
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-31917 - High Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through &amp;lt;= ... https://www.thehackerwire.com/vulnerability/CVE-2026-31917/ https://t.co/0W8qwfmY6K

    Post summary

    The tweet announces CVE-2026-31917, a high‑severity SQL injection flaw in weDevs WP ERP, but offers no proof‑of‑concept, exploit details, or mitigation information.

    0000051
    135 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-31917: HIGH] Critical SQL Injection vulnerability discovered in weDevs WP ERP software, versions from n/a through &lt;= 1.16.10. Ensure immediate patch to prevent cyber attacks.#cve,CVE-2026-31917,#cybersecurity https://cvefind.com/CVE-2026-31917

    Post summary

    The tweet announces a high‑severity SQL injection flaw in weDevs WP ERP and urges immediate patching, but it gives no PoC, exploit code, or evidence of wild exploitation.

    0000056
    602 followersView on X

Explore more