Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33350

27
FAUCET Score

LORIS (Longitudinal Online Research and Imaging System) versions prior to 27.0.3 and 28.0.1 contain a SQL injection vulnerability in the MRI feedback popup window of the imaging browser module. This self-hosted neuroimaging research data management application is susceptible to unauthorized data access and modification through malicious SQL queries. The vulnerability affects the application's ability to securely handle user input in specific code sections related to imaging feedback functionality. The vulnerability carries a CVSS 3.1 severity rating of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. Attack complexity is low, indicating that exploitation does not require specialized conditions or insider knowledge. The primary impact is confidentiality compromise, allowing attackers to access sensitive neuroimaging research data stored on affected servers, though data integrity and system availability are not directly impacted by this particular vulnerability. Currently, there is no evidence of active exploitation in the wild, as the vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on relevant threat tracking lists. The EPSS score of 0.00044 indicates this vulnerability is currently exploited less frequently than the majority of public CVEs. Organizations running affected LORIS versions should apply patches 27.0.3 or 28.0.1 to remediate this risk, particularly given the sensitive nature of neuroimaging research data.

Impacted Technologies

VendorProductVersion(s)CPE
< 27.0.3CPE matchmatch criteria
cpe:2.3:a:mcgill:loris:*:*:*:*:*:*:*:*
28.0.0CPE matchmatch criteria
cpe:2.3:a:mcgill:loris:28.0.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
15.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 2nd percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / aces/Loris/security/advisories/GHSA-9r29-6jgc-3ggh
Vendor Advisory