CVE-2019-1010191: Marginalia Project Marginalia
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
marginalia < 1.6 is affected by: SQL Injection. The impact is: The impact is a injection of any SQL queries when a user controller argument is added as a component. The component is: Affects users that add a component that is user controller, for instance a parameter or a header. The attack vector is: Hacker inputs a SQL to a vulnerable vector(header, http parameter, etc). The fixed version is: 1.6.
Affected products
- Marginalia Project Marginalia: before 1.6.0 (fixed in 1.6.0)
Published 2019-07-24. Last modified 2026-06-17.