CVE-2025-11251
Modified Modified - Updated After Analysis

SQL Injection in Dayneks E-Commerce Platform Allows Data Access

Vulnerability report for CVE-2025-11251, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-27

Last updated on: 2026-06-04

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows SQL Injection. This issue affects E-Commerce Platform: through 27022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-27
Last Modified
2026-06-04
Generated
2026-07-27
AI Q&A
2026-02-27
EPSS Evaluated
2026-07-26
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
daynex woyio *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an SQL Injection issue found in the Dayneks Software Industry and Trade Inc. E-Commerce Platform. SQL Injection occurs when special elements in SQL commands are not properly neutralized, allowing an attacker to manipulate the database queries executed by the application.

Detection Guidance

I don't know

Impact Analysis

This vulnerability can have a severe impact as it allows attackers to execute arbitrary SQL commands on the affected e-commerce platform. This can lead to unauthorized access to sensitive data, data modification, or deletion, and potentially full system compromise.

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-11251. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart