CVE-2024-25722: Qanything

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.

Affected products

  • Qanything Qanything: before 1.2.0 (fixed in 1.2.0)

Published 2024-02-11. Last modified 2026-06-17.