CVE-2019-25696: Marmotech Kados

Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers can submit malicious SQL statements in the language_tag parameter to extract sensitive database information or modify data.

Affected products

Published 2026-04-05. Last modified 2026-07-24.