Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42665 |
|
Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.
Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.
|
| CVE-2026-40771 |
|
Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.
Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.
|
| CVE-2026-42381 |
|
Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.
Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.
|
| CVE-2026-40766 |
|
Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.
Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.
|
| CVE-2026-40798 |
|
Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.
Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.
|
| CVE-2026-42386 |
|
Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.
Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.
|
| CVE-2026-39502 |
|
Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.
Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.
|
| CVE-2026-39530 |
|
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
|
| CVE-2026-40762 |
|
Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.
Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.
|
| CVE-2026-39492 |
|
Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
|
| CVE-2026-39511 |
|
Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.
Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.
|
| CVE-2026-39512 |
|
Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
|
| CVE-2026-39493 |
|
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
|
| CVE-2026-39519 |
|
Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
|
| CVE-2026-39441 |
|
Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.
Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.
|
| CVE-2026-24637 |
|
Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.
Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.
|
| CVE-2026-50890 |
|
SQL Injection in sqli (CVE-2026-50890)
SQL injection in sqli (CVE-2026-50890). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48114 |
|
SQL Injection in sqli (CVE-2026-48114)
SQL injection in sqli (CVE-2026-48114). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39196 |
|
SQL Injection in sqli (CVE-2026-39196)
SQL injection in sqli (CVE-2026-39196). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38812 |
|
SQL Injection in sqli (CVE-2026-38812)
SQL injection in sqli (CVE-2026-38812). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36670 |
|
SQL Injection in sqli (CVE-2026-36670)
SQL injection in sqli (CVE-2026-36670). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25746 |
|
SQL Injection in wordpress (CVE-2019-25746)
SQL injection in wordpress (CVE-2019-25746). Confidential information can be exposed externally.
|
| CVE-2016-20073 |
|
SQL Injection in wordpress (CVE-2016-20073)
SQL injection in wordpress (CVE-2016-20073). Confidential information can be exposed externally.
|
| CVE-2016-20072 |
|
SQL Injection in wordpress (CVE-2016-20072)
SQL injection in wordpress (CVE-2016-20072). Confidential information can be exposed externally.
|
| CVE-2016-20071 |
|
SQL Injection in wordpress (CVE-2016-20071)
SQL injection in wordpress (CVE-2016-20071). Confidential information can be exposed externally.
|
| CVE-2016-20069 |
|
SQL Injection in wordpress (CVE-2016-20069)
SQL injection in wordpress (CVE-2016-20069). Confidential information can be exposed externally.
|
| CVE-2016-20068 |
|
SQL Injection in wordpress (CVE-2016-20068)
SQL injection in wordpress (CVE-2016-20068). Confidential information can be exposed externally.
|
| CVE-2026-12206 |
|
Vulnerability in sqli (CVE-2026-12206)
vulnerability in sqli (CVE-2026-12206). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12188 |
|
Vulnerability in sqli (CVE-2026-12188)
vulnerability in sqli (CVE-2026-12188). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12175 |
|
Vulnerability in sqli (CVE-2026-12175)
vulnerability in sqli (CVE-2026-12175). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6428 |
|
SQL Injection in sqli (CVE-2026-6428)
SQL injection in sqli (CVE-2026-6428). Confidential information can be exposed externally. Exploitable via `GET /cgi-bin/koha/reports/catalogue_out.pl`.
|
| CVE-2026-9848 |
|
SQL Injection in wordpress (CVE-2026-9848)
SQL injection in wordpress (CVE-2026-9848). Confidential information can be exposed externally. Exploitable via ``posts_request``.
|
| CVE-2026-12131 |
|
Vulnerability in sqli (CVE-2026-12131)
vulnerability in sqli (CVE-2026-12131). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41581 |
|
SQL Injection in sqli (CVE-2026-41581)
SQL injection in sqli (CVE-2026-41581). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48613 |
|
SQL Injection in sqli (CVE-2026-48613)
SQL injection in sqli (CVE-2026-48613). Confidential information can be exposed externally.
|
| CVE-2026-45418 |
|
SQL Injection in sqli (CVE-2026-45418)
SQL injection in sqli (CVE-2026-45418). Successful exploitation can lead to full system takeover. Exploitable via `POST /actions/subtitle_edit.php`.
|
| CVE-2026-45060 |
|
SQL Injection in sqli (CVE-2026-45060)
SQL injection in sqli (CVE-2026-45060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42647 |
|
SQL Injection in sqli (CVE-2026-42647)
SQL injection in sqli (CVE-2026-42647). Confidential information can be exposed externally.
|
| CVE-2026-39494 |
|
SQL Injection in sqli (CVE-2026-39494)
SQL injection in sqli (CVE-2026-39494). Confidential information can be exposed externally.
|
| CVE-2026-46622 |
|
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any...
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database — through SQL injection, a leaked backup, a misconf...
|
| CVE-2026-38581 |
|
SQL Injection in sqli (CVE-2026-38581)
SQL injection in sqli (CVE-2026-38581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53474 |
|
SQL Injection in github.com/kubev2v/migration-planner (CVE-2026-53474)
SQL injection in github.com/kubev2v/migration-planner (CVE-2026-53474). Confidential information can be exposed externally. Mitigation: upgrade to `0.13.5` or later.
|
| CVE-2026-52758 |
|
SQL Injection in sqli (CVE-2026-52758)
SQL injection in sqli (CVE-2026-52758). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49498 |
|
SQL Injection in sqli (CVE-2026-49498)
SQL injection in sqli (CVE-2026-49498). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3018 |
|
SQL Injection in wordpress (CVE-2026-3018)
SQL injection in wordpress (CVE-2026-3018). Confidential information can be exposed externally.
|
| CVE-2026-3326 |
|
SQL Injection in wordpress (CVE-2026-3326)
SQL injection in wordpress (CVE-2026-3326). Confidential information can be exposed externally.
|
| CVE-2026-50636 |
|
SQL Injection in limesurvey/limesurvey (CVE-2026-50636)
SQL injection in limesurvey/limesurvey (CVE-2026-50636). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8025 |
|
SQL Injection in sqli (CVE-2026-8025)
SQL injection in sqli (CVE-2026-8025). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7486 |
|
SQL Injection in sqli (CVE-2026-7486)
SQL injection in sqli (CVE-2026-7486). Successful exploitation can lead to full system takeover.
|
| CVE-2017-20247 |
|
SQL Injection in wordpress (CVE-2017-20247)
SQL injection in wordpress (CVE-2017-20247). Confidential information can be exposed externally.
|