Search Results (20373 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-74011 2 Revmakx, Wordpress 2 Infinitewp Client, Wordpress 2026-08-20 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9.
CVE-2026-68566 2 Repute Infosystems, Wordpress 2 Bookingpress Appointment Booking Pro, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
CVE-2026-66649 2 E-plugins, Wordpress 2 Directory Pro, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
CVE-2025-15688 2 Themegoods, Wordpress 2 Capella, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
CVE-2026-76785 1 Amirsanni 1 Mini-inventory-and-sales-management-system 2026-08-20 6.3 Medium
A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument orderBy/orderFormat results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-73185 2 Wordpress, Wpo-hr 2 Wordpress, Ngg Smart Image Search 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
CVE-2026-66680 2 Plainwaire, Wordpress 2 Locatoraid Store Locator, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
CVE-2026-66668 2 Peepso, Wordpress 2 Community By Peepso, Wordpress 2026-08-20 8.5 High
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
CVE-2026-16019 1 Faydam Innovation 1 Faydam Datalogger 2026-08-20 9.8 Critical
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0.
CVE-2026-77019 1 Codeastro 1 Apartment Visitor Management System 2026-08-20 7.3 High
A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the argument secode can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-76635 1 Baserproject 1 Basercms 2026-08-20 7.2 High
baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL statements across sequence update, CSV export, and table management operations. Attackers can chain a backup restore code injection flaw, where PHP code outside class definitions in schema files executes unconditionally upon loading, to plant malicious table names and trigger error-based SQL injection that retrieves database version, schema contents, and arbitrary data from the PostgreSQL backend.
CVE-2026-76996 1 Sourcecodester 1 Simple Online Food Ordering System 2026-08-20 7.3 High
A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
CVE-2026-49392 1 Wazuh 1 Wazuh 2026-08-20 5.3 Medium
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows systems, FIMDBCreator::encodeString() does not escape the value. A local user who can create a filename in a File Integrity Monitoring directory can inject a UNION SELECT expression when wazuh-syscheckd processes or deletes that path. The confirmed primitive manipulates SELECT result sets consumed by the FIM code; stacked statements and remote code execution were not demonstrated. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.
CVE-2026-66592 2 Rtcamp, Wordpress 2 Rtmedia For Wordpress, Buddypress And Bbpress, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
CVE-2026-71866 1 Orval-labs 1 Orval 2026-08-20 N/A
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double quote in a schema property name is emitted into the generated zod.object({...}) schema without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts and zod object-key generation. This issue is fixed in version 8.21.0.
CVE-2026-75876 1 Xianrendzw 1 Easyreport 2026-08-20 6.3 Medium
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of the file ModuleController.java of the component Move Operations. Such manipulation of the argument sourcePath leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-76050 1 Sourcecodester 1 Simple Online Food Ordering System 2026-08-20 7.3 High
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
CVE-2026-19899 1 Sourcecodester 1 Class And Exam Timetabling System 2026-08-20 7.3 High
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
CVE-2025-10592 1 Itsourcecode 2 Online Public Access Catalog, Online Public Access Catalog Opac 2026-08-20 6.3 Medium
A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search_field/search_text leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
CVE-2026-76240 1 Eidetic-labs 1 Stigmem 2026-08-20 N/A
stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a schema name were derived from tenant, request, or user input. Fixed in 0.9.0a2, which adds identifier quoting and validation. As a workaround, only configure schema names from trusted deployment configuration.