SQL Injection in Trex Digital Manufacturing's Trex MES
45Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8
from disclosure to weapon0 days
Published on NVDSep 30
1st PoCJul 30
exploitation probability
—
observed exploitation
nono source reports it
1 public exploit(s)
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection.
This issue affects Trex MES: through 2026-09-29.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Trex Digital Smart Manufacturing Systems Inc. · Trex MESpublic PoCs found — 1
githubgithub.com/Hasanuyarrr/CVE-2026-18782-TREX-MES-Uygulamalarinda-SQL-Zafiyeti★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.