Export limit exceeded: 21146 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (21146 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87781 | 2026-10-10 | 8.6 High | ||
| The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | ||||
| CVE-2026-104753 | 2026-10-10 | 4.1 Medium | ||
| The Rank Math SEO WordPress plugin before 1.0.280 does not properly sanitise and escape a parameter before using it in a SQL query, allowing high-privilege users such as administrators to perform SQL injection attacks. | ||||
| CVE-2026-96653 | 2026-10-10 | 6.5 Medium | ||
| The WP Directory Kit plugin for WordPress is vulnerable to time-based SQL Injection via 'display_name' Profile Field (Second-Order) in all versions up to, and including, 1.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order injection: a Subscriber stores a display_name containing a single quote via their own profile, which WordPress preserves verbatim; the payload is then triggered when WdkCachedUserEditor::update_listings_user_editor() re-reads that stored value and passes it unsanitized to the SQL sink. | ||||
| CVE-2026-96662 | 2026-10-10 | 7.5 High | ||
| The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-107712 | 2026-10-10 | 6.5 Medium | ||
| The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_month' parameter in all versions up to, and including, 2.1.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a regression vulnerability — a capability check introduced in versions 2.0.19.11–2.0.19.14 to address CVE-2024-50425 was removed in version 2.1, meaning any authenticated subscriber-level account can reach the vulnerable handler with no nonce validation required. | ||||
| CVE-2026-104023 | 2026-10-10 | 4.9 Medium | ||
| The Smart Popup by Supsystic plugin for WordPress is vulnerable to generic SQL Injection via the 'sidx' parameter in all versions up to, and including, 1.13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-104724 | 2026-10-10 | 5.3 Medium | ||
| The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to generic SQL Injection via FireBox Form Display Condition in all versions up to, and including, 3.1.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. On fresh installations of version 3.1.10 and later, exploitation requires administrator-level access; however, on sites upgraded from a version prior to 3.1.10, the preserveCampaignRoleAccess() migration grants the edit_fireboxes capability to any role that previously held edit_posts, reducing the minimum required privilege to Author-level. | ||||
| CVE-2026-80381 | 1 Ibm | 1 Guardium Data Protection | 2026-10-10 | 9.8 Critical |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute unauthorized SQL statements due to SQL injection. | ||||
| CVE-2026-108474 | 2026-10-10 | 9.8 Critical | ||
| In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions | ||||
| CVE-2026-73663 | 2 Freepbx, Sangoma | 2 Missedcall, Freepbx | 2026-10-09 | 9.8 Critical |
| FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4. | ||||
| CVE-2026-107384 | 1 Mariadb-corporation | 1 Mariadb-connector-nodejs | 2026-10-09 | 8.1 High |
| MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL. This can update columns the application did not intend to expose and can append arbitrary SQL with the database user's privileges. The option is disabled by default, and serialized-object handling used when it is disabled is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4. | ||||
| CVE-2026-96331 | 2026-10-09 | 9.3 Critical | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdreams Ajax Search Pro ajax-search-pro allows Blind SQL Injection.This issue affects Ajax Search Pro: from n/a through 4.29.1. | ||||
| CVE-2026-95610 | 2026-10-09 | 8.5 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UpSolution UpSolution Core us-core allows Blind SQL Injection.This issue affects UpSolution Core: from n/a through 9.3. | ||||
| CVE-2026-94663 | 2026-10-09 | 8.5 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Blind SQL Injection.This issue affects ProfileGrid: from n/a through 6.0.0.2. | ||||
| CVE-2026-108125 | 2026-10-09 | N/A | ||
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author. This issue affects wp-post-author version 4.0.0 prior to 4.1.0. | ||||
| CVE-2026-108124 | 2026-10-09 | 4.9 Medium | ||
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author. This issue affects wp-post-author before 4.1.0. | ||||
| CVE-2026-107803 | 1 Processmaker | 1 Processmaker | 2026-10-09 | 6.5 Medium |
| ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering()` concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3. | ||||
| CVE-2026-76270 | 1 Splunk | 1 Splunk Enterprise | 2026-10-09 | 6.5 Medium |
| In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module filtering to access all relevant data available through the affected Representational State Transfer (REST) API, including private SPL2 module definitions belonging to other users. The vulnerability is possible because Splunk Enterprise and Splunk Cloud Platform do not parameterize user-supplied values before using them in database queries for SPL2 module filtering. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation. Splunk Enterprise versions 10.2.x, 10.0.x, and 9.4.x are not affected. | ||||
| CVE-2026-106097 | 2026-10-09 | 6.8 Medium | ||
| The Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints, which are accessible to any user holding site-administration capabilities; on a WordPress Multisite network those belong to subsite Administrators, allowing a subsite Administrator who is not a network Super Admin to perform UNION-based SQL injection against shared network tables and disclose network-wide data such as other users' password hashes. | ||||
| CVE-2026-96328 | 2026-10-09 | 9.3 Critical | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jegtheme JNews - Pay Writer jnews-pay-writer allows Blind SQL Injection.This issue affects JNews - Pay Writer: from n/a through 12.0.1. | ||||