Export limit exceeded: 19928 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (19928 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-13009 2 Wordpress, Wupsales 2 Wordpress, Ai Copilot – Content Generator 2026-07-23 6.5 Medium
The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The required waic-nonce is emitted on the front-end whenever the [waic_form] or [aiwu-form] shortcode is rendered, enabling contributor-level users who can publish shortcodes to obtain a valid nonce and reach the vulnerable AJAX handler, which performs no capability check beyond nonce verification when the shortcodes are not already embedded in a page.
CVE-2026-15448 2 Tickera, Wordpress 2 Tickera – Sell Tickets & Manage Events, Wordpress 2026-07-23 6.5 Medium
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-61949 2 Bookly, Wordpress 2 Bookly, Wordpress 2026-07-23 9.3 Critical
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
CVE-2026-65454 2026-07-23 8.5 High
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
CVE-2026-65526 2 Themeisle, Wordpress 2 Visualizer, Wordpress 2026-07-23 8.5 High
Contributor SQL Injection in Visualizer <= 4.0.6 versions.
CVE-2026-65532 2 Persianscript, Wordpress 2 Persian Woocommerce Sms, Wordpress 2026-07-23 7.6 High
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
CVE-2026-56292 1 Acymailing.com 1 Acymailing.com Acymailing Extension For Joomla 2026-07-23 N/A
Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.
CVE-2026-57832 2026-07-23 N/A
Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.
CVE-2026-57831 2026-07-23 N/A
Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
CVE-2026-61950 2 Themetechmount, Wordpress 2 Truebooker, Wordpress 2026-07-23 9.3 Critical
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
CVE-2026-61948 2026-07-23 9.3 Critical
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-15906 2026-07-23 6.5 Medium
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-7253 1 Ibm 3 Ibm Watson Speech Services Cartridge, Sterling B2b Integrator, Sterling File Gateway 2026-07-23 6 Medium
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVE-2026-59526 2 Romancode, Wordpress 2 Mapsvg, Wordpress 2026-07-23 9.3 Critical
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-65451 2 Romancode, Wordpress 2 Mapsvg, Wordpress 2026-07-23 8.5 High
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-15761 2 Tickera, Wordpress 2 Tickera – Sell Tickets & Manage Events, Wordpress 2026-07-23 6.5 Medium
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable code path is reachable by users holding the plugin's custom Staff role, as the plugin's add_required_capabilities() function grants that role the edit_tc_tickets_instances capability, providing access to the tc_tickets_instances admin list screen where the filter is applied.
CVE-2026-59525 2026-07-23 9.3 Critical
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
CVE-2026-65494 2026-07-23 7.1 High
Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
CVE-2026-52348 2026-07-22 9.8 Critical
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
CVE-2026-64880 2026-07-22 7.1 High
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.