#Sqlite
2 postsBugForge - Daily - Tanuki (Jul 14, 2026)
Tanuki's XML deck import blacklists the single quote and numeric entities on the deck name, but allows the standard ' entity, which decodes to a quote and reaches a concatenated SQL query.
SQLi SQL Injection Injection Xml Filter Bypass WAF Bypass Sqlite
Posted on 2026-07-14 20:00 7 min read
BugForge - Daily - Cafe Club (Jan 11, 2026)
A SQL Injection vulnerability exists in the product API endpoint where the product ID parameter is directly concatenated into a SQLite query without…
SQLi Sqlite
Posted on 2026-01-11 20:00 4 min read