CVE z tagiem sql-injection — 200 wyników. ← Wszystkie tagi

CVE-2016-2386 🔴 Łataj teraz KEV

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

9.8 CVSS
44.5% EPSS
CVE-2026-21643 🔴 Łataj teraz KEV
network

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via sp…

9.8 CVSS
33.9% EPSS
CVE-2023-5204 🔴 Łataj teraz

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparat…

9.8 CVSS
87.0% EPSS
CVE-2022-1768 🔴 Łataj teraz

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. …

9.8 CVSS
86.1% EPSS
CVE-2022-1453 🔴 Łataj teraz

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it…

9.8 CVSS
62.1% EPSS
CVE-2024-49681 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Se…

9.3 CVSS
51.3% EPSS
sql-injection 2024-10-24
CVE-2023-3197 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lac…

9.8 CVSS
36.8% EPSS
CVE-2024-50491 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.

9.3 CVSS
37.7% EPSS
CVE-2022-44588 🔴 Łataj teraz

Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.

9.9 CVSS
34.0% EPSS
CVE-2022-45805 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a thr…

8.2 CVSS
39.4% EPSS
paytmsql-injection 2023-11-03
CVE-2023-28787 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.

9.3 CVSS
32.0% EPSS
sql-injection 2024-03-26
CVE-2024-2387 ⚪ Do wiadomości

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, an…

6.1 CVSS
36.6% EPSS
sql-injection 2024-03-20
CVE-2023-32590 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category.This issue affects Subscribe to Category: from n/a thro…

9.3 CVSS
19.3% EPSS
CVE-2023-50839 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support…

9.3 CVSS
16.3% EPSS
CVE-2023-24000 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GamiPress gamipress allows SQL Injection.This issue affects GamiPress: from n/a through 2.5.7.

8.2 CVSS
21.2% EPSS
CVE-2006-5344 🟠 Łataj w tym tygodniu
appsos

Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_3gl, aka Vu…

9.0 CVSS
10.5% EPSS
CVE-2023-45657 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSIMYTH Nexter allows SQL Injection.This issue affects Nexter: from n/a through 2.0.3.

8.5 CVSS
12.2% EPSS
CVE-2026-3396 🟡 Monitoruj

WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due to insufficient escaping on the user supplied param…

7.5 CVSS
17.0% EPSS
sql-injection 2026-04-08
CVE-2023-5412 🟠 Łataj w tym tygodniu

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.2 due to insufficient escaping on the user supplied parameter…

8.8 CVSS
9.8% EPSS
CVE-2022-1505 🟠 Łataj w tym tygodniu

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This…

9.8 CVSS
3.4% EPSS
CVE-2006-5675 🟠 Łataj w tym tygodniu

Multiple unspecified vulnerabilities in Pentaho Business Intelligence (BI) Suite before 1.2 RC3 (1.2.0.470-RC3) have unknown impact and attack vectors, related to "MySQL Scripts need changes for security," possibly SQL i…

10.0 CVSS
1.6% EPSS
CVE-2022-34132 🟠 Łataj w tym tygodniu

Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.

9.8 CVSS
1.9% EPSS
joranisql-injection 2022-06-28
CVE-2023-25960 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zen…

10.0 CVSS
0.3% EPSS
CVE-2024-1711 🟠 Łataj w tym tygodniu

The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due to insufficient escaping on the user supplied parameter and lack of suffi…

9.8 CVSS
1.2% EPSS
sql-injection 2024-03-20
CVE-2021-4340 🔴 Łataj teraz

The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of suff…

9.8 CVSS
0.8% EPSS
CVE-2023-36529 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress…

9.9 CVSS
0.2% EPSS
CVE-2006-5603 🔴 Łataj teraz

SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details ar…

9.8 CVSS
0.7% EPSS
CVE-2026-34612 🔴 Łataj teraz

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the fo…

9.9 CVSS
0.2% EPSS
CVE-2026-23696 🟠 Łataj w tym tygodniu

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. A…

9.9 CVSS
0.1% EPSS
sql-injection 2026-04-07
CVE-2021-27130 🔴 Łataj teraz

Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload.

9.8 CVSS
0.5% EPSS
CVE-2024-29667 🟠 Łataj w tym tygodniu

SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges and obtain sensitive information via the ids parameter.

9.8 CVSS
0.5% EPSS
sql-injection 2024-03-29
CVE-2024-2804 🟠 Łataj w tym tygodniu

The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up to, and including, 2.0.11 due to insufficient escaping on the user supplied parameter and lack of su…

9.8 CVSS
0.5% EPSS
sql-injection 2024-04-09
CVE-2023-2449 🟠 Łataj w tym tygodniu

The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on …

9.8 CVSS
0.5% EPSS
CVE-2026-41460 🔴 Łataj teraz

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated…

9.8 CVSS
0.4% EPSS
CVE-2024-28389 🟠 Łataj w tym tygodniu

SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail(…

9.8 CVSS
0.3% EPSS
sql-injection 2024-03-19
CVE-2024-25910 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

9.8 CVSS
0.3% EPSS
CVE-2020-29297 🔴 Łataj teraz

Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.

9.8 CVSS
0.3% EPSS
CVE-2022-29650 🟠 Łataj w tym tygodniu

Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.

9.8 CVSS
0.3% EPSS
CVE-2022-36759 🟠 Łataj w tym tygodniu

Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.

9.8 CVSS
0.2% EPSS
CVE-2023-2297 🔴 Łataj teraz

The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password res…

9.8 CVSS
0.2% EPSS
CVE-2023-6173 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeoSOFT Software TeoBASE allows SQL Injection.This issue affects TeoBASE: through 27032024. NOTE: The vendor was conta…

9.8 CVSS
0.1% EPSS
sql-injection 2024-03-27
CVE-2025-65133 🟠 Łataj w tym tygodniu

A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manip…

9.8 CVSS
0.1% EPSS
sql-injection 2026-04-14
CVE-2024-29732 🟠 Łataj w tym tygodniu

A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was f…

9.8 CVSS
0.1% EPSS
sql-injection 2024-03-21
CVE-2024-36058 🟠 Łataj w tym tygodniu

The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library user…

9.8 CVSS
0.1% EPSS
sql-injection 2026-04-07
CVE-2026-28430 🟠 Łataj w tym tygodniu

Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQL commands via the custom_dates paramete…

9.8 CVSS
0.1% EPSS
CVE-2026-5963 🟠 Łataj w tym tygodniu

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

9.8 CVSS
0.1% EPSS
sql-injection 2026-04-20
CVE-2026-5964 🟠 Łataj w tym tygodniu

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

9.8 CVSS
0.1% EPSS
sql-injection 2026-04-20
CVE-2023-38382 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows SQL Injection.This issue affects Subscribe to Ca…

9.8 CVSS
0.1% EPSS
CVE-2024-28303 🟠 Łataj w tym tygodniu

Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php.

9.8 CVSS
0.1% EPSS
sql-injection 2024-03-19
CVE-2024-2865 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection.This issue affects Quality Management System: through 2…

9.8 CVSS
0.1% EPSS
sql-injection 2024-03-25
CVE-2026-40351 🟠 Łataj w tym tygodniu

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB…

9.8 CVSS
0.1% EPSS
sql-injection 2026-04-17
CVE-2026-28443 🔴 Łataj teraz

OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sort.field parameter. This issue has been patched in version 1.20.0.

9.8 CVSS
0.0% EPSS
CVE-2026-28501 🟠 Łataj w tym tygodniu

WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components. The application fa…

9.8 CVSS
0.0% EPSS
wwbnsql-injection 2026-03-06
CVE-2025-56212 🟠 Łataj w tym tygodniu

phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.

9.8 CVSS
0.0% EPSS
CVE-2025-56214 🟠 Łataj w tym tygodniu

phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.

9.8 CVSS
0.0% EPSS
CVE-2026-35614 🟠 Łataj w tym tygodniu

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. This vulnerability is fixed in 16.14.0 and 15.104.0.

9.8 CVSS
0.0% EPSS
frappesql-injection 2026-04-07
CVE-2026-33088 🟠 Łataj w tym tygodniu

Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.

9.8 CVSS
0.0% EPSS
CVE-2025-11252 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.This issue affects windesk.Fm: before v2…

9.8 CVSS
0.0% EPSS
CVE-2026-30930 🔴 Łataj teraz

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized system monitoring data. The normalize() me…

9.8 CVSS
0.0% EPSS
CVE-2025-62319 🟠 Łataj w tym tygodniu

Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors o…

9.8 CVSS
0.0% EPSS
sql-injection 2026-03-16
CVE-2025-67829 🟠 Łataj w tym tygodniu

Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.

9.8 CVSS
0.0% EPSS
CVE-2025-67830 🟠 Łataj w tym tygodniu

Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.

9.8 CVSS
0.0% EPSS
CVE-2026-33352 🔴 Łataj teraz

WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. The `doNotShowCats` request paramet…

9.8 CVSS
0.0% EPSS
CVE-2026-30532 🔴 Łataj teraz

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.

9.8 CVSS
0.0% EPSS
CVE-2026-30533 🔴 Łataj teraz

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.

9.8 CVSS
0.0% EPSS
CVE-2026-32714 🔴 Łataj teraz

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python's str.format() to construct SQL queries …

9.8 CVSS
0.0% EPSS
CVE-2026-34220 🟠 Łataj w tym tygodniu

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpr…

9.8 CVSS
0.0% EPSS
CVE-2026-35184 🔴 Łataj teraz

EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.

9.8 CVSS
0.0% EPSS
CVE-2025-63939 🟠 Łataj w tym tygodniu

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter.

9.8 CVSS
0.0% EPSS
sql-injection 2026-04-14
CVE-2025-65135 🟠 Łataj w tym tygodniu

In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter.

9.8 CVSS
0.0% EPSS
sql-injection 2026-04-14
CVE-2026-37339 🟠 Łataj w tym tygodniu

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.

9.8 CVSS
0.0% EPSS
sql-injection 2026-04-16
CVE-2026-37340 🟠 Łataj w tym tygodniu

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.

9.8 CVSS
0.0% EPSS
sql-injection 2026-04-16
CVE-2026-37345 🟠 Łataj w tym tygodniu

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.

9.8 CVSS
0.0% EPSS
sql-injection 2026-04-16
CVE-2026-33082 🔴 Łataj teraz

DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST /de2api/datasetTree/…

9.8 CVSS
0.0% EPSS
CVE-2026-33122 🔴 Łataj teraz

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource update process. When a new table definition is added during a d…

9.8 CVSS
0.0% EPSS
CVE-2026-34018 🟠 Łataj w tym tygodniu

An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product.

9.8 CVSS
0.0% EPSS
CVE-2026-34400 🟠 Łataj w tym tygodniu

Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms d…

9.8 CVSS
0.0% EPSS
CVE-2026-30530 🔴 Łataj teraz

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to t…

9.8 CVSS
0.0% EPSS
CVE-2006-5335 🟠 Łataj w tym tygodniu
appsos

Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) Vuln# DB04 and sys.dbms_cdc_impdp in the (a) Change Data Capture (C…

9.0 CVSS
3.9% EPSS
oraclesql-injection 2006-10-18
CVE-2006-5336 🟠 Łataj w tym tygodniu
appsos

Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and have unknown impact and remote authenticated attack vectors related to (1) sys.dbms_cdc_ipublish (…

9.0 CVSS
3.9% EPSS
oraclesql-injection 2006-10-18
CVE-2026-34885 🟡 Monitoruj

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a throug…

8.5 CVSS
6.2% EPSS
sql-injection 2026-04-06
CVE-2006-5341 🟠 Łataj w tym tygodniu
appsos

Multiple unspecified vulnerabilities in XMLDB component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors, aka (1) Vuln# DB14 and (2) DB15 related to xdb.dbms_…

9.0 CVSS
3.6% EPSS
oraclesql-injection 2006-10-18
CVE-2006-5332 🟠 Łataj w tym tygodniu
appsos

Unspecified vulnerability in xdb.dbms_xdbz in the XMLDB component for Oracle Database 9.2.0.6 and 10.1.0.4 has unknown impact and remote authenticated attack vectors, aka Vuln# DB01. NOTE: as of 20061023, Oracle has not…

9.0 CVSS
3.6% EPSS
oraclesql-injection 2006-10-18
CVE-2006-5236 🟡 Monitoruj

SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL commands via the search_user parameter.

7.5 CVSS
10.9% EPSS
CVE-2006-5338 🟠 Łataj w tym tygodniu
appsos

Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5 has unknown impact and remote authenticated attack vectors related to sys.dbms_sqltune, aka Vuln# DB10. NOTE: as of 20061023, Oracle has …

9.0 CVSS
3.3% EPSS
oraclesql-injection 2006-10-18
CVE-2024-38795 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro-plugin allows SQL Injection.This issue affects ListingPro: from n/a through <= 2.9.…

9.3 CVSS
0.7% EPSS
cridiosql-injection 2024-08-29
CVE-2026-39109 🟠 Łataj w tym tygodniu

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipu…

9.4 CVSS
0.2% EPSS
sql-injection 2026-04-20
CVE-2024-43978 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from n/a through < 6.9.8.

9.3 CVSS
0.6% EPSS
CVE-2026-37338 🟠 Łataj w tym tygodniu

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.

9.4 CVSS
0.0% EPSS
sql-injection 2026-04-16
CVE-2024-43976 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from n/a through <= 6.9.7.

9.3 CVSS
0.5% EPSS
CVE-2024-39622 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro allows SQL Injection.This issue affects ListingPro: from n/a through <= 2.9.4.

9.3 CVSS
0.4% EPSS
cridiosql-injection 2024-08-29
CVE-2024-49305 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Email Verification for WooCommerce emails-verification-for-woocommerce allows SQL Injection.This issue affec…

9.3 CVSS
0.4% EPSS
sql-injection 2024-10-17
CVE-2024-50479 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocommerce Quote Calculator woo-quote-calculator-order allows Blind SQL Injection.This issue affects Wooc…

9.3 CVSS
0.4% EPSS
CVE-2024-44004 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection.This issue affects WPCargo Track & Trace: from n/a throu…

9.3 CVSS
0.4% EPSS
CVE-2024-47350 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITHEMES YITH WooCommerce Ajax Search yith-woocommerce-ajax-search.This issue affects YITH WooCommerce Ajax Search: fr…

9.3 CVSS
0.3% EPSS
sql-injection 2024-10-06
CVE-2023-52215 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue …

9.3 CVSS
0.3% EPSS
CVE-2024-49246 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anand23 Ajax Rating with Custom Login ajax-rating-with-custom-login allows SQL Injection.This issue affects Ajax Ratin…

9.3 CVSS
0.3% EPSS
sql-injection 2024-10-17
CVE-2025-47682 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notificati…

9.3 CVSS
0.2% EPSS
CVE-2025-30622 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in torsteino PostMash postmash-custom allows SQL Injection.This issue affects PostMash: from n/a through <= 1.0.3.

9.3 CVSS
0.2% EPSS
sql-injection 2025-04-01
CVE-2024-25927 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Joel Starnes postMash – custom post order.This issue affects postMash – custom post order: from n/a through 1.2.0.

9.3 CVSS
0.2% EPSS
jmashsql-injection 2024-02-28
CVE-2024-47331 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ninja Team Multi Step for Contact Form cf7-multi-step allows SQL Injection.This issue affects Multi Step for Contact F…

9.3 CVSS
0.2% EPSS
CVE-2023-49750 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate & Submitting Coupons WordPress Theme.This issue affects Couponis - Affiliate & Submit…

9.3 CVSS
0.2% EPSS
CVE-2023-49776 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.

9.3 CVSS
0.2% EPSS
dmrysql-injection 2023-12-20
CVE-2023-48738 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porto Theme Porto Theme - Functionality.This issue affects Porto Theme - Functionality: from n/a before 2.12.1.

9.3 CVSS
0.1% EPSS
CVE-2023-40010 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in realmag777 HUSKY – Products Filter for WooCommerce Professional.This issue affects HUSKY – Products Filter for WooComm…

9.3 CVSS
0.1% EPSS
CVE-2023-49752 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoon themes Adifier - Classified Ads WordPress Theme.This issue affects Adifier - Classified Ads WordPress Theme: fro…

9.3 CVSS
0.1% EPSS
CVE-2023-51423 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgn…

9.3 CVSS
0.1% EPSS
CVE-2023-51469 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestres do WP Checkout Mestres WP.This issue affects Checkout Mestres WP: from n/a through 7.1.9.6.

9.3 CVSS
0.1% EPSS
CVE-2025-49915 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notificati…

9.3 CVSS
0.1% EPSS
sql-injection 2025-10-22
CVE-2025-60062 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer tplayer-html5-audio-player-with-playlist allows SQL Injection.This issue affects tPlayer: from n/a th…

9.3 CVSS
0.1% EPSS
sql-injection 2025-12-18
CVE-2025-58951 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management for WooCommerce scw-seat-reservation allows SQL Injection.This issue affe…

9.3 CVSS
0.1% EPSS
sql-injection 2025-12-18
CVE-2026-27413 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14…

9.3 CVSS
0.0% EPSS
sql-injection 2026-03-19
CVE-2026-22484 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL Injection.This issue affects Lisfinity Core: from n/a through <= 1.5.0.

9.3 CVSS
0.0% EPSS
sql-injection 2026-03-25
CVE-2026-24993 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL…

9.3 CVSS
0.0% EPSS
sql-injection 2026-03-25
CVE-2026-25340 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind SQL Injection.This issue affects Jobmonster: from n/a through < 4.8.4.

9.3 CVSS
0.0% EPSS
sql-injection 2026-03-25
CVE-2026-25377 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jobsearch Chat: from n/…

9.3 CVSS
0.0% EPSS
sql-injection 2026-03-25
CVE-2026-25371 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allows Blind SQL Injection.This issue affects Lumise Product Designer: from …

9.3 CVSS
0.0% EPSS
sql-injection 2026-03-25
CVE-2026-31920 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind SQL Injection.This i…

9.3 CVSS
0.0% EPSS
sql-injection 2026-03-25
CVE-2026-32499 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9.

9.3 CVSS
0.0% EPSS
sql-injection 2026-03-25
CVE-2026-32539 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Revisions revisionary allows Blind SQL Injection.This issue affects PublishPress Revisions: …

9.3 CVSS
0.0% EPSS
sql-injection 2026-03-25
CVE-2025-23993 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allows SQL Injection.This issue affects Felan Framework: from n/a through <=…

9.3 CVSS
0.0% EPSS
sql-injection 2026-01-08
CVE-2025-67928 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allows Blind SQL Injection.This issue affects Automotive Listings: from n/a …

9.3 CVSS
0.0% EPSS
sql-injection 2026-01-08
CVE-2025-49055 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allows Blind SQL Injection.This issue affects WP Lead Capturing P…

9.3 CVSS
0.0% EPSS
sql-injection 2026-01-22
CVE-2025-67945 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite – WooCommerce integration woo-mailerlite allows SQL Injection.This issue affects MailerLite – Wo…

9.3 CVSS
0.0% EPSS
sql-injection 2026-01-22
CVE-2025-68034 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp allows SQL Injection.This issue affects CleverReach® WP: from n/a through …

9.3 CVSS
0.0% EPSS
sql-injection 2026-01-22
CVE-2026-33134 🔴 Łataj teraz

WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_produto.php endpoint. The vulnerability allows an authenticat…

9.3 CVSS
0.0% EPSS
CVE-2025-49931 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetSearch jet-search allows Blind SQL Injection.This issue affects JetSearch: from n/a through <= 3.5.10.

9.3 CVSS
0.0% EPSS
sql-injection 2025-10-22
CVE-2025-59557 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts Addons learts-addons allows SQL Injection.This issue affects Learts Addons: from n/a through < 1.7.5.

9.3 CVSS
0.0% EPSS
sql-injection 2025-10-22
CVE-2025-48089 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rainbow-Themes Education WordPress Theme | HiStudy histudy allows SQL Injection.This issue affects Education WordPress…

9.3 CVSS
0.0% EPSS
sql-injection 2025-11-06
CVE-2025-52773 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiecor HieCOR Payment Gateway Plugin hcv4-payment-gateway allows SQL Injection.This issue affects HieCOR Payment Gatew…

9.3 CVSS
0.0% EPSS
sql-injection 2025-11-06
CVE-2026-33615 🟠 Łataj w tym tygodniu

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. This can result in a total…

9.1 CVSS
0.1% EPSS
CVE-2026-32698 🟠 Łataj w tym tygodniu

OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack via a custom field's name. When that custom field was u…

9.1 CVSS
0.0% EPSS
CVE-2026-34374 🔴 Łataj teraz

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by interpolating a stream key directly into the query string without para…

9.1 CVSS
0.0% EPSS
CVE-2026-37347 🟠 Łataj w tym tygodniu

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php.

9.1 CVSS
0.0% EPSS
sql-injection 2026-04-16
CVE-2024-27718 🟡 Monitoruj

SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.

7.8 CVSS
6.3% EPSS
sql-injection 2024-03-05
CVE-2023-5466 🟡 Monitoruj

The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.1 due to insufficient escaping on the user supplied parameter and lack of sufficie…

8.8 CVSS
0.4% EPSS
CVE-2026-40901 🟠 Łataj w tym tygodniu

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer deserializ…

8.8 CVSS
0.4% EPSS
CVE-2022-4290 🟡 Monitoruj

The Cyr to Lat plugin for WordPress is vulnerable to authenticated SQL Injection via the 'ctl_sanitize_title' function in versions up to, and including, 3.5 due to insufficient escaping on the user supplied parameter and…

8.8 CVSS
0.3% EPSS
CVE-2023-3677 🟡 Monitoruj

The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in versions up to, and including, 1.2.89 due to insufficient escaping on the user supplied parameter and la…

8.8 CVSS
0.3% EPSS
rednaosql-injection 2023-08-31
CVE-2024-3211 🟡 Monitoruj

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of the ec_addtocart shortcode in all versions up to, and including, 5.6.3 due to insufficient escaping…

8.8 CVSS
0.3% EPSS
sql-injection 2024-04-12
CVE-2023-5435 🟠 Łataj w tym tygodniu

The Up down image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and la…

8.8 CVSS
0.3% EPSS
CVE-2023-5437 🟠 Łataj w tym tygodniu

The WP fade in text news plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of suffi…

8.8 CVSS
0.3% EPSS
CVE-2023-5464 🟠 Łataj w tym tygodniu

The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.1 due to insufficient escaping on the user supplied parameter and lack of …

8.8 CVSS
0.3% EPSS
CVE-2023-0579 🟠 Łataj w tym tygodniu

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL I…

8.8 CVSS
0.3% EPSS
CVE-2023-2237 🟡 Monitoruj

The WP Replicate Post plugin for WordPress is vulnerable to SQL Injection via the post_id parameter in versions up to, and including, 4.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficie…

8.8 CVSS
0.3% EPSS
yudizsql-injection 2023-06-09
CVE-2023-4999 🟠 Łataj w tym tygodniu

The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-scrolling] shortcode in versions up to, and including, 9.2 due to insufficient escaping on the user s…

8.8 CVSS
0.3% EPSS
CVE-2023-5465 🟡 Monitoruj

The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.5 due to insufficient escaping on the user supplied parameter and lack of suffici…

8.8 CVSS
0.3% EPSS
CVE-2023-1471 🟡 Monitoruj

The WP Popup Banners plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' parameter in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of suffi…

8.8 CVSS
0.3% EPSS
CVE-2023-5434 🟠 Łataj w tym tygodniu

The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.1 due to insufficient escaping on the user supplied parameter and lack of s…

8.8 CVSS
0.3% EPSS
CVE-2023-5436 🟠 Łataj w tym tygodniu

The Vertical marquee plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

8.8 CVSS
0.3% EPSS
CVE-2023-5438 🟠 Łataj w tym tygodniu

The wp image slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of suffici…

8.8 CVSS
0.3% EPSS
CVE-2023-5439 🟠 Łataj w tym tygodniu

The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.0 due to insufficient escaping on the user supplied parameter and lack of suf…

8.8 CVSS
0.3% EPSS
CVE-2023-2201 🟡 Monitoruj

The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.6.8 due to insufficient escaping on the user supplied parameter and lack of sufficient …

8.8 CVSS
0.3% EPSS
CVE-2023-5709 🟠 Łataj w tym tygodniu

The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficie…

8.8 CVSS
0.2% EPSS
CVE-2023-5428 🟠 Łataj w tym tygodniu

The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0 due to insufficient escaping on the user supplied parameter an…

8.8 CVSS
0.2% EPSS
CVE-2022-45373 🟡 Monitoruj

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics allows SQL Injection.This issue affects Slimstat Analytics: from n/a throu…

8.8 CVSS
0.2% EPSS
CVE-2026-26794 🟠 Łataj w tym tygodniu

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations via a crafted HTTP reques…

8.8 CVSS
0.2% EPSS
CVE-2024-51606 🟡 Monitoruj

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Blrt Blrt WP Embed blrt-wp-embed allows SQL Injection.This issue affects Blrt WP Embed: from n/a through <= 1.6.9.

8.8 CVSS
0.2% EPSS
blrtsql-injection 2024-11-09
CVE-2024-51608 🟡 Monitoruj

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in colinph970 AmaDiscount amadiscount allows SQL Injection.This issue affects AmaDiscount: from n/a through <= 1.0.

8.8 CVSS
0.2% EPSS
CVE-2023-2229 🟡 Monitoruj

The Quick Post Duplicator for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient …

8.8 CVSS
0.2% EPSS
CVE-2026-32950 🟠 Łataj w tym tygodniu

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remot…

8.8 CVSS
0.2% EPSS
CVE-2023-5430 🟠 Łataj w tym tygodniu

The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.0 due to insufficient escaping on the user supplied parameter and lack of sufficie…

8.8 CVSS
0.2% EPSS
CVE-2023-4598 🟠 Łataj w tym tygodniu

The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 5.0.9 due to insufficient escaping on the user supplied parameter and lack of suffic…

8.8 CVSS
0.2% EPSS
CVE-2023-5315 🟡 Monitoruj

The Google Maps made Simple plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 0.6 due to insufficient escaping on the user supplied parameter and lack of suf…

8.8 CVSS
0.2% EPSS
CVE-2023-5429 🟠 Łataj w tym tygodniu

The Information Reel plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 10.0 due to insufficient escaping on the user supplied parameter and lack of sufficien…

8.8 CVSS
0.2% EPSS
CVE-2023-5431 🟠 Łataj w tym tygodniu

The Left right image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and…

8.8 CVSS
0.2% EPSS
CVE-2023-5433 🟠 Łataj w tym tygodniu

The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient p…

8.8 CVSS
0.2% EPSS
CVE-2023-5336 🟡 Monitoruj

The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied …

CVE-2023-41652 🟡 Monitoruj

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6.

8.2 CVSS
3.1% EPSS
CVE-2025-10655 🟠 Łataj w tym tygodniu

SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.

8.8 CVSS
0.1% EPSS
CVE-2026-33288 🟡 Monitoruj

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerability exists in the SuiteCRM authentication mechanisms…

8.8 CVSS
0.1% EPSS
CVE-2026-40978 🟡 Monitoruj
cloud

SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (f…

8.8 CVSS
0.1% EPSS
vmwaresql-injection 2026-04-28
CVE-2026-30711 🟡 Monitoruj

Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session.inc.php file via the referer and user-agent.

8.8 CVSS
0.0% EPSS
sql-injection 2026-03-19
CVE-2026-3334 🟡 Monitoruj

The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. This is due to insufficient …

8.8 CVSS
0.0% EPSS
sql-injection 2026-03-21
CVE-2026-31858 🟡 Monitoruj

Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to ElementIndexesController in CVE-2026-25495. The exact same SQL injectio…

8.8 CVSS
0.0% EPSS
CVE-2026-32628 🟠 Łataj w tym tygodniu

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL injection vulnerability in the built-in SQL Agent plugin allows any…

8.8 CVSS
0.0% EPSS
CVE-2026-30881 🟡 Monitoruj

Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the statistics AJAX endpoint. The parameters date_start and date_end from $_REQUEST are embedded directly i…

8.8 CVSS
0.0% EPSS
CVE-2026-3023 🟡 Monitoruj

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/pets/print-tags'. This vulnerability could allow an authenticated user to alter a POST requ…

8.8 CVSS
0.0% EPSS
wakymasql-injection 2026-03-16
CVE-2026-29099 🟡 Monitoruj

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the `retrieve()` function in `include/OutboundEmail/OutboundEmail.php` fails t…

8.8 CVSS
0.0% EPSS
CVE-2026-32888 🟠 Łataj w tym tygodniu

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items search functionality. When the custom attribute search feature…

8.8 CVSS
0.0% EPSS
CVE-2026-33025 🟡 Monitoruj

AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() method of Object.php. The $_POST['sort'] array keys are used directly as SQL column identifiers insi…

8.8 CVSS
0.0% EPSS
wwbnsql-injection 2026-03-20
CVE-2026-4815 🟡 Monitoruj

A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve, create, update and delete database via 'calls[0][message_ids][]' parameter in '/supportboard/includ…

8.8 CVSS
0.0% EPSS
CVE-2026-33755 🟠 Łataj w tym tygodniu

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injection vulnerability in the JMAP `Contact/query` endpoint allows…

8.8 CVSS
0.0% EPSS
CVE-2026-30531 🟠 Łataj w tym tygodniu

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize user input supplied to t…

8.8 CVSS
0.0% EPSS
CVE-2025-47902 🟡 Monitoruj

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This issue affects Time Provider 4100: before 2.5.

8.8 CVSS
0.0% EPSS
CVE-2026-28805 🟠 Łataj w tym tygodniu

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Based Blind SQL Injection throu…

8.8 CVSS
0.0% EPSS
CVE-2026-35470 🟠 Łataj w tym tygodniu

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across different modules in OpenSTAManager contain an SQL Injection vulnerability. T…

8.8 CVSS
0.0% EPSS
CVE-2026-35395 🟠 Łataj w tym tygodniu

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in dao/memorando/DespachoDAO.php. The id_memorando parame…

8.8 CVSS
0.0% EPSS
CVE-2026-39318 🟡 Monitoruj

ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the endpoints `/GroupPropsFormRowOps.php`, `/PersonCustomFieldsRowOps.php`, and `/FamilyCustomFieldsRow…

8.8 CVSS
0.0% EPSS
sql-injection 2026-04-07
CVE-2026-39319 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was found in the endpoint /FundRaiserEditor.php in ChurchCRM. A user has to be authenticated but doesn't ne…

8.8 CVSS
0.0% EPSS
CVE-2026-39326 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyTypeEditor.php in ChurchCRM. Authenticated users with the role isMenuOptionsEnabled …

8.8 CVSS
0.0% EPSS
CVE-2026-39327 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /MemberRoleChange.php in ChurchCRM 7.0.5. Authenticated users with the role Manage Groups & R…

8.8 CVSS
0.0% EPSS
CVE-2026-39329 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /EventNames.php in ChurchCRM. Authenticated users with AddEvent privileges can inject SQL via the new…

8.8 CVSS
0.0% EPSS
CVE-2026-39330 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyAssign.php in ChurchCRM. Authenticated users with the role Manage Groups & Roles (Ma…

8.8 CVSS
0.0% EPSS
CVE-2026-39334 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsIndividual.php in ChurchCRM 7.0.5. Authenticated users without any specific privileg…

8.8 CVSS
0.0% EPSS
CVE-2026-39342 🟠 Łataj w tym tygodniu

ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection. The authenticated user requires access to Data/Report…

8.8 CVSS
0.0% EPSS
CVE-2026-24913 🟡 Monitoruj

SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.

8.8 CVSS
0.0% EPSS
iczsql-injection 2026-04-08
CVE-2026-34185 🟠 Łataj w tym tygodniu 🇵🇱 CERT.pl

Hydrosystem Control System is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining fu…

8.8 CVSS
0.0% EPSS
CVE-2026-39815 🟡 Monitoruj
network

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending cra…

8.8 CVSS
0.0% EPSS
CVE-2026-30813 🟡 Monitoruj

Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search. This issue affects Pandora FMS: from 777 through 800

8.8 CVSS
0.0% EPSS
articasql-injection 2026-04-13