PoC Archive PoC Archive

tag

Blind-Sqli

LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208) KEV EPSS 89%
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc) web Patched
CVE-2026-42208webCRITICAL 9.8Patched2026-07-11PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391 web Patched
CVE-2025-11391webCRITICAL 9.8Patched2026-07-06WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
CVE-2026-3180 web Unverified
CVE-2026-3180webHIGHUnverified2026-07-05The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
CVE-2026-49772 web Patched
CVE-2026-49772webCRITICAL 9.3Patched2026-07-05SonicWall SMA 8200v Cross-Parameter Blind SQL Injection to Root (CVE-2026-4112)
CVE-2026-4112 (SonicWall Advisory SNWLID-2026-0003) network Unverified
CVE-2026-4112networkHIGH 7.2Unverified2026-07-05JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
CVE-2026-49048 (Advisory ID JOOMCCK-2026-001) web Unpatched
CVE-2026-49048webCRITICAL 8.7Unpatched2026-07-05JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
CVE-2026-49079 web Unverified
CVE-2026-49079webHIGH 7.5Unverified2026-07-05ITFlow Time-Based Blind SQL Injection via agent/ajax.php expires Parameter (CVE-2026-54597)
CVE-2026-54597 web Unverified
CVE-2026-54597webHIGHUnverified2026-07-05Ghost CMS Content API — Unauthenticated Blind SQL Injection (CVE-2026-26980) EPSS 70%
CVE-2026-26980 web Patched
CVE-2026-26980webCRITICALPatched2026-07-05