๐Ÿ” CVE Alert

CVE-2026-44706

HIGH 8.5

Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Values

CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
0th

Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type date or number using the is_greater_than or is_less_than operators, user-supplied values in the values field of the filter payload are interpolated directly into the SQL query without parameterization. Any authenticated user with access to an account can exploit this to execute arbitrary SQL via time-based blind injection. This affects /api/v1/accounts/{account_id}/conversations/filter, /api/v1/accounts/{account_id}/contacts/filter, and /api/v1/accounts/{account_id}/custom_attribute_definitions. This vulnerability is fixed in 4.11.2.

CWE CWE-89
Vendor chatwoot
Product chatwoot
Published May 26, 2026
Last Updated May 26, 2026
Stay Ahead of the Next One

Get instant alerts for chatwoot chatwoot

Be the first to know when new high vulnerabilities affecting chatwoot chatwoot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

chatwoot / chatwoot
>= 2.2.0, < 4.11.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/chatwoot/chatwoot/security/advisories/GHSA-9pgm-75gg-6948