CVE-2024-55586
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's position is that this is intended behavior.
Published 2024-12-10. Last modified 2026-06-17.