Export limit exceeded: 21091 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (21091 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105149 | 1 Moosocial | 1 Moosocial | 2026-10-06 | 7.3 High |
| A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-105166 | 1 Kishor-23 | 2 Food-waste-management-system, Food Waste Management System | 2026-10-06 | 7.3 High |
| A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-39764 | 2 Radiustheme, Wordpress-extensions | 2 Radius Booking — Booking Calendar For Appointments & Services, Radius Booking | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments & Services <= 1.0.19 versions. | ||||
| CVE-2026-39771 | 2 Mightynetworks Vs Buddyboss, Wordpress-extensions | 2 Buddyboss Platform, Buddyboss Platform | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions. | ||||
| CVE-2026-39785 | 2 Serhii Pasiuk, Wordpress-extensions | 2 Gmedia Photo Gallery, Gmedia Photo Gallery | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions. | ||||
| CVE-2026-39795 | 2 Brewlabs, Wordpress-extensions | 2 Sendpress Newsletters, Sendpress Newsletters | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. | ||||
| CVE-2026-41555 | 2 Weblizar, Wordpress-extensions | 2 Newsletter Subscription Form – User Subscriptions Form, Capture Email, Newsletter Subscription Form – User Subscriptions Form, Capture Email | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. | ||||
| CVE-2026-95865 | 2 Beaverbuilder, Wordpress-extensions | 2 Beaver Builder Page Builder – Drag And Drop Website Builder, Beaver Builder Page Builder | 2026-10-06 | 6.5 Medium |
| The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable get_autosuggest_values AJAX endpoint is reachable by any Contributor who owns a draft post, as the required fl_ajax_update nonce is emitted into the block editor for any user who can edit a Beaver Builder post type. | ||||
| CVE-2026-71298 | 2 Maestro, Redhat | 3 Maestro, Multicluster Engine, Multicluster Engine For Kubernetes | 2026-10-06 | 6.4 Medium |
| A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database. | ||||
| CVE-2026-42414 | 2 Cridio, Wordpress-extensions | 2 Listingpro, Listingpro | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in ListingPro <= 2.9.12 versions. | ||||
| CVE-2026-42415 | 2 Portotheme, Wordpress-extensions | 2 Functionality, Porto Theme | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions. | ||||
| CVE-2026-42416 | 2 Andondesign, Wordpress-extensions | 2 Udesign, Udesign Core | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in UDesign Core <= 4.15.0 versions. | ||||
| CVE-2026-42417 | 2 Reputeinfosystems, Wordpress-extensions | 2 Armember, Armember Premium | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions. | ||||
| CVE-2026-105317 | 2 Cozmoslabs, Wordpress-extensions | 2 Paid Member Subscriptions, Paid Member Subscriptions | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions. | ||||
| CVE-2026-88416 | 1 Mcms | 1 Mcms | 2026-10-06 | 9.8 Critical |
| MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature. | ||||
| CVE-2026-105919 | 1 Kusalkasilva | 1 Learning-management-system | 2026-10-06 | 7.3 High |
| A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The affected element is the function mysql_query of the file admin/login.php of the component Administrator Login Endpoint. The manipulation of the argument username/password results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-105845 | 2026-10-06 | 9.8 Critical | ||
| Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27. | ||||
| CVE-2026-76570 | 2 Joomcode, Joomcoder.com | 2 Jc Tables, Jctables Extension For Joomla | 2026-10-06 | 9.1 Critical |
| Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries. | ||||
| CVE-2026-105469 | 1 Girishsaraf | 1 Online-appointment-booking-system | 2026-10-06 | 7.3 High |
| A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-105386 | 1 Onetwothreeneth | 1 Hospitalmanagementsystem | 2026-10-06 | 7.3 High |
| A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the function get of the file print.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | ||||