CVE-2026-31825 | Sylius up to 2.2.2 orderBy sql injection (GHSA-xcwx-r2gw-w93m)
A vulnerability, which was classified as critical, has been found in Sylius up to 2.2.2. Affected by this issue is the function orderBy. This manipulation causes sql injection.
This vulnerability is tracked as CVE-2026-31825. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.