CVE-2026-2395: Xpoda Türkiye Informatics Technology Inc No Code Platform
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.1.3 before 4.1.4.
Affected products
- Xpoda Türkiye Informatics Technology Inc No Code Platform: from 4.1.3, before 4.1.4 (fixed in 4.1.4)
Published 2026-07-22. Last modified 2026-07-30.