The CVE-2026-75979 vulnerability affects EasyReport up to 2.0.17.0522_Beta, specifically in the DesignerController.java file's execSqlText/previewSqlText function, allowing for improper neutralization of special elements used in a template engine. This vulnerability has a low CVSS score of 2.1 and can be exploited remotely. Security teams and administrators responsible for EasyReport installations should [truncated]
A SQL injection vulnerability exists in xianrendzw EasyReport up to version 2.0.17.0522_Beta. The vulnerability resides in the `execute` function of a REST endpoint component, where improper sanitization of the `reportParams` argument allows remote attackers to inject malicious SQL commands. The vulnerability has a CVSS 4.0 base score of 5.3 (MEDIUM severity) with network attack vector, low attack complex [truncated]