PoC Archive PoC Archive

tag

Blind-Sqli

Critical
LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc)· LiteLLM Proxy — open-source LLM/AI gateway (22,000+ GitHub stars) fronting OpenAI, Anthropic, and other model provider APIs patched
Critical
PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391· PPOM for WooCommerce (woocommerce-product-addon plugin) patched
High
WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
CVE-2026-3180· WordPress "Contest Gallery" plugin unpatched
Critical
The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
CVE-2026-49772· The Events Calendar (WordPress plugin, StellarWP / Liquid Web), experimental tec/v1 REST API patched
High
SonicWall SMA 8200v Cross-Parameter Blind SQL Injection to Root (CVE-2026-4112)
CVE-2026-4112 (SonicWall Advisory SNWLID-2026-0003)· SonicWall SMA 8200v management console (Jetty + Struts 2, port 8443) unpatched
Critical
JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
CVE-2026-49048 (Advisory ID JOOMCCK-2026-001)· JoomCCK (com_joomcck) — Content Construction Kit extension for Joomla, by JoomCoder unpatched
High
JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
CVE-2026-49079· JetSearch plugin for WordPress unpatched
High
ITFlow Time-Based Blind SQL Injection via agent/ajax.php expires Parameter (CVE-2026-54597)
CVE-2026-54597· ITFlow (open-source MSP/IT management platform) unpatched
Critical
Ghost CMS Content API — Unauthenticated Blind SQL Injection (CVE-2026-26980)
CVE-2026-26980· Ghost CMS patched