Articles tagged SQL Injection
-
VulnerabilityAcyMailing SMTP Newsletter SQL Injection (CVE-2026-57739)
CVE-2026-57739 is a CVSS 9.3 blind SQL injection flaw in the AcyMailing WordPress newsletter plugin, reported exploited by VulnCheck KEV.
-
VulnerabilityCKAN SQL Injection (CVE-2026-42031)
CVE-2026-42031 is a CVSS 9.8 SQL injection flaw in the datastore_search_sql API of open-source data portal platform CKAN, reported exploited by VulnCheck KEV.
-
VulnerabilityGeoDirectory SQL Injection (CVE-2026-84813)
CVE-2026-84813 is a CVSS 9.3 unauthenticated SQL injection flaw in the GeoDirectory WordPress plugin, reported exploited by VulnCheck KEV.
-
VulnerabilityGeoTools SQL Injection (CVE-2026-76904)
CVE-2026-76904 is a CVSS 9.8 SQL injection flaw in GeoTools PostGIS integration via jsonArrayContains, reported exploited by VulnCheck KEV.
-
VulnerabilityWooCommerce Lottery SQL Injection (CVE-2026-18884)
CVE-2026-18884 is a CVSS 7.5 unauthenticated SQL injection in the WooCommerce Lottery WordPress plugin, per VulnCheck alone.
-
VulnerabilityCisco Secure Email Gateway SQL Injection (CVE-2026-76461)
CVE-2026-76461 is a CVSS 9.8 SQL injection flaw in Cisco Secure Email Gateway's AsyncOS email parsing that allows unauthenticated root command execution.
-
VulnerabilitySangoma Switchvox SMB Edition SQL Injection (CVE-2026-9586)
CVE-2026-9586 is a CVSS 9.8 unauthenticated SQL injection in Sangoma Switchvox SMB Edition 8.3 enabling remote code execution. KEV-listed Sept. 2, 2026.
-
Vulnerability7 SourceCodester Class and Exam Timetabling System 1.0 CVEs (CVE-2026-86220)
Seven separate CVEs (CVE-2026-86220 through 86225 and 86298) document the same unauthenticated SQL injection flaw repeated across different admin panel files in SourceCodester Class and Exam Timetabling System 1.0, with public exploit code for each.
-
Vulnerability5 itsourcecode Sales and Inventory System 1.0 CVEs (CVE-2026-86232)
Five separate CVEs (CVE-2026-86232 through 86236) document the same unauthenticated SQL injection flaw repeated across different pages of itsourcecode Sales and Inventory System 1.0, with public exploit code for each.
-
Vulnerability2 PostgreSQL Anonymizer CVEs (CVE-2026-19634)
Two more PostgreSQL Anonymizer vulnerabilities (CVE-2026-19634, CVE-2026-83534) let a table owner or masked user reach superuser-level code execution through the extension's import and parallel-anonymization functions.
-
VulnerabilityRedaxo CMS MyEvents Addon 2.2.1 SQL Injection (CVE-2018-25319)
CVE-2018-25319 is a CVSS 7.1 high-severity SQL injection in the MyEvents addon for Redaxo CMS, only recently scored by NVD despite the original disclosure dating to 2018.