tag
Cwe-89
Critical
wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf·
WordPress core (REST API /batch/v1, WP_Query::author__not_in)
patched
Critical
LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc)·
LiteLLM Proxy — open-source LLM/AI gateway (22,000+ GitHub stars) fronting OpenAI, Anthropic, and other model provider APIs
patched
Critical
PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391·
PPOM for WooCommerce (woocommerce-product-addon plugin)
patched
Critical
FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819)
CVE-2025-57819·
Sangoma FreePBX administrator web UI (admin/ajax.php, endpoint module)
patched
Critical
Django QuerySet/Q Object SQL Injection via `_connector` Kwarg (CVE-2025-64459)
CVE-2025-64459·
Django ORM (QuerySet.filter() / Q object construction)
patched
Critical
"Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
CVE-2025-65354·
PHP-based "Grocery" web application, Grocery/search_products_itname.php endpoint
unpatched
High
ZoneMinder — Second-Order SQL Injection via Event Rename (CVE-2026-27470)
CVE-2026-27470·
ZoneMinder
patched
Critical
WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379
CVE-2026-6379·
WordPress plugin "WP Photo Album Plus" (WPPA+) by opajaap
patched
Critical
Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 (GHSA-xxh2-68g9-8jqr)·
Ormar (async Python ORM, commonly used with FastAPI/Starlette)
patched
Critical
JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
CVE-2026-49048 (Advisory ID JOOMCCK-2026-001)·
JoomCCK (com_joomcck) — Content Construction Kit extension for Joomla, by JoomCoder
unpatched
High
JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
CVE-2026-49079·
JetSearch plugin for WordPress
unpatched
High
ITFlow Time-Based Blind SQL Injection via agent/ajax.php expires Parameter (CVE-2026-54597)
CVE-2026-54597·
ITFlow (open-source MSP/IT management platform)
unpatched
High
ITFlow SQL Injection via recurring_invoice_frequency (CVE-2026-54596)
CVE-2026-54596·
ITFlow (open-source MSP/IT management platform)
unpatched
Critical
CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)
CVE-2026-37749·
CodeAstro Simple Attendance Management System 1.0
unpatched
High
Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)
CVE-2026-2576·
Business Directory Plugin (Easy Listing Directories) for WordPress
patched
Medium
Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980
CVE-2026-23980·
Apache Superset
patched