๐Ÿ” CVE Alert

CVE-2026-34455

UNKNOWN 0.0

Hi.Events: SQL Injection via Unvalidated sort_by Query Parameter in Multiple Repository Classes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
9th

Hi.Events is an open-source event management and ticket selling platform. From version 0.8.0-beta.1 to before version 1.7.1-beta, multiple repository classes pass the user-supplied sort_by query parameter directly to Eloquent's orderBy() without validation, enabling SQL injection. The application uses PostgreSQL which supports stacked queries. This issue has been patched in version 1.7.1-beta.

CWE CWE-89
Vendor hieventsdev
Product hi.events
Published Apr 1, 2026
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for hieventsdev hi.events

Be the first to know when new unknown vulnerabilities affecting hieventsdev hi.events are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

HiEventsDev / Hi.Events
>= 0.8.0-beta.1, < 1.7.1-beta

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/HiEventsDev/Hi.Events/security/advisories/GHSA-2qcp-24fh-fx6p github.com: https://github.com/HiEventsDev/Hi.Events/pull/1128 github.com: https://github.com/HiEventsDev/Hi.Events/commit/01e1aee28d7249f235fdcca8e3a34e88214dcde9 github.com: https://github.com/HiEventsDev/Hi.Events/releases/tag/v1.7.1-beta