Export limit exceeded: 21175 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (21175 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-89234 | 2026-10-11 | 8.6 High | ||
| The WP-Partner WordPress plugin through 1.2.1 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database. | ||||
| CVE-2026-89232 | 2026-10-11 | 8.6 High | ||
| The Recordbrowser WordPress plugin through 1.1.7 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database. | ||||
| CVE-2026-89213 | 2026-10-11 | 8.6 High | ||
| The Llavero.io WordPress plugin through 0.1.4 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database. | ||||
| CVE-2026-89195 | 2026-10-11 | 8.6 High | ||
| The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database. | ||||
| CVE-2026-88930 | 2026-10-11 | 8.6 High | ||
| The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before using it in an SQL statement, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-81420 | 2026-10-11 | 8.6 High | ||
| The Tcard WP WordPress plugin through 1.8.0 does not sanitise and escape a parameter before using it in a SQL statement in one of its unauthenticated AJAX actions, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-62117 | 2026-10-11 | 8.5 High | ||
| Subscriber SQL Injection in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions. | ||||
| CVE-2026-62031 | 2026-10-11 | 9.3 Critical | ||
| Unauthenticated SQL Injection in uListing <= 2.2.0 versions. | ||||
| CVE-2026-45440 | 2026-10-11 | 7.6 High | ||
| Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions. | ||||
| CVE-2026-42722 | 2026-10-11 | 7.6 High | ||
| Administrator SQL Injection in Frontend Admin by DynamiApps <= 3.29.13 versions. | ||||
| CVE-2026-42717 | 2026-10-11 | 7.6 High | ||
| Administrator SQL Injection in Leyka <= 3.32.3 versions. | ||||
| CVE-2026-42712 | 2026-10-11 | 8.5 High | ||
| Subscriber SQL Injection in Qode Tours <= 3.1.3.2 versions. | ||||
| CVE-2026-42633 | 2026-10-11 | 8.5 High | ||
| Subscriber SQL Injection in Events Manager <= 7.4.6 versions. | ||||
| CVE-2026-40800 | 2026-10-11 | 9.3 Critical | ||
| Subscriber SQL Injection in ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes <= 1.5.3 versions. | ||||
| CVE-2026-105889 | 2026-10-11 | 9.3 Critical | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6. | ||||
| CVE-2026-103695 | 2026-10-11 | 8.6 High | ||
| The Mobile builder WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-108571 | 1 Xinhu | 1 Rainrock Rockoa | 2026-10-11 | 7.3 High |
| A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. This impacts the function kqjcmdModel::returnchuli of the file webmain/task/openapi/openkqjAction.php of the component Openkqj Action. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-108569 | 1 Furion | 1 .net Framework | 2026-10-11 | 6.3 Medium |
| A vulnerability was identified in Furion .NET Framework up to 4.9.9.92. The impacted element is the function String.Replace of the file framework/Furion/Templates/Extensions/StringRenderExtensions.cs. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-108541 | 1 Highwarden | 1 Super Store Finder | 2026-10-11 | 6.3 Medium |
| A vulnerability has been found in highwarden Super Store Finder up to 3.8. Affected is an unknown function of the file /products/superstorefinder/index.php. The manipulation of the argument lat/lng leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 3.9 is able to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | ||||
| CVE-2026-104753 | 2026-10-10 | 4.1 Medium | ||
| The Rank Math SEO WordPress plugin before 1.0.280 does not properly sanitise and escape a parameter before using it in a SQL query, allowing high-privilege users such as administrators to perform SQL injection attacks. | ||||