SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpointReferenceshttps://github.com/vran-dev/databasir/issues/283https://zeroday.endlessparadox.com/posts/cve-2025-66944/