PoC Archive PoC Archive

tag

Cwe-89

Critical
wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf· WordPress core (REST API /batch/v1, WP_Query::author__not_in) patched
Critical
LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc)· LiteLLM Proxy — open-source LLM/AI gateway (22,000+ GitHub stars) fronting OpenAI, Anthropic, and other model provider APIs patched
Critical
PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391· PPOM for WooCommerce (woocommerce-product-addon plugin) patched
Critical
FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819)
CVE-2025-57819· Sangoma FreePBX administrator web UI (admin/ajax.php, endpoint module) patched
Critical
Django QuerySet/Q Object SQL Injection via `_connector` Kwarg (CVE-2025-64459)
CVE-2025-64459· Django ORM (QuerySet.filter() / Q object construction) patched
Critical
"Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
CVE-2025-65354· PHP-based "Grocery" web application, Grocery/search_products_itname.php endpoint unpatched
High
ZoneMinder — Second-Order SQL Injection via Event Rename (CVE-2026-27470)
CVE-2026-27470· ZoneMinder patched
Critical
WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379
CVE-2026-6379· WordPress plugin "WP Photo Album Plus" (WPPA+) by opajaap patched
Critical
Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 (GHSA-xxh2-68g9-8jqr)· Ormar (async Python ORM, commonly used with FastAPI/Starlette) patched
Critical
JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
CVE-2026-49048 (Advisory ID JOOMCCK-2026-001)· JoomCCK (com_joomcck) — Content Construction Kit extension for Joomla, by JoomCoder unpatched
High
JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
CVE-2026-49079· JetSearch plugin for WordPress unpatched
High
ITFlow Time-Based Blind SQL Injection via agent/ajax.php expires Parameter (CVE-2026-54597)
CVE-2026-54597· ITFlow (open-source MSP/IT management platform) unpatched
High
ITFlow SQL Injection via recurring_invoice_frequency (CVE-2026-54596)
CVE-2026-54596· ITFlow (open-source MSP/IT management platform) unpatched
Critical
CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)
CVE-2026-37749· CodeAstro Simple Attendance Management System 1.0 unpatched
High
Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)
CVE-2026-2576· Business Directory Plugin (Easy Listing Directories) for WordPress patched
Medium
Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980
CVE-2026-23980· Apache Superset patched