Export limit exceeded: 21175 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (21175 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-89234 2026-10-11 8.6 High
The WP-Partner WordPress plugin through 1.2.1 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
CVE-2026-89232 2026-10-11 8.6 High
The Recordbrowser WordPress plugin through 1.1.7 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
CVE-2026-89213 2026-10-11 8.6 High
The Llavero.io WordPress plugin through 0.1.4 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.
CVE-2026-89195 2026-10-11 8.6 High
The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.
CVE-2026-88930 2026-10-11 8.6 High
The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before using it in an SQL statement, allowing unauthenticated users to perform SQL injection attacks.
CVE-2026-81420 2026-10-11 8.6 High
The Tcard WP WordPress plugin through 1.8.0 does not sanitise and escape a parameter before using it in a SQL statement in one of its unauthenticated AJAX actions, allowing unauthenticated users to perform SQL injection attacks.
CVE-2026-62117 2026-10-11 8.5 High
Subscriber SQL Injection in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
CVE-2026-62031 2026-10-11 9.3 Critical
Unauthenticated SQL Injection in uListing <= 2.2.0 versions.
CVE-2026-45440 2026-10-11 7.6 High
Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions.
CVE-2026-42722 2026-10-11 7.6 High
Administrator SQL Injection in Frontend Admin by DynamiApps <= 3.29.13 versions.
CVE-2026-42717 2026-10-11 7.6 High
Administrator SQL Injection in Leyka <= 3.32.3 versions.
CVE-2026-42712 2026-10-11 8.5 High
Subscriber SQL Injection in Qode Tours <= 3.1.3.2 versions.
CVE-2026-42633 2026-10-11 8.5 High
Subscriber SQL Injection in Events Manager <= 7.4.6 versions.
CVE-2026-40800 2026-10-11 9.3 Critical
Subscriber SQL Injection in ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes <= 1.5.3 versions.
CVE-2026-105889 2026-10-11 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.
CVE-2026-103695 2026-10-11 8.6 High
The Mobile builder WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
CVE-2026-108571 1 Xinhu 1 Rainrock Rockoa 2026-10-11 7.3 High
A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. This impacts the function kqjcmdModel::returnchuli of the file webmain/task/openapi/openkqjAction.php of the component Openkqj Action. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-108569 1 Furion 1 .net Framework 2026-10-11 6.3 Medium
A vulnerability was identified in Furion .NET Framework up to 4.9.9.92. The impacted element is the function String.Replace of the file framework/Furion/Templates/Extensions/StringRenderExtensions.cs. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-108541 1 Highwarden 1 Super Store Finder 2026-10-11 6.3 Medium
A vulnerability has been found in highwarden Super Store Finder up to 3.8. Affected is an unknown function of the file /products/superstorefinder/index.php. The manipulation of the argument lat/lng leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 3.9 is able to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVE-2026-104753 2026-10-10 4.1 Medium
The Rank Math SEO WordPress plugin before 1.0.280 does not properly sanitise and escape a parameter before using it in a SQL query, allowing high-privilege users such as administrators to perform SQL injection attacks.