tag
Sql-Injection
Critical
wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf·
WordPress core (REST API /batch/v1, WP_Query::author__not_in)
patched
Critical
LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc)·
LiteLLM Proxy — open-source LLM/AI gateway (22,000+ GitHub stars) fronting OpenAI, Anthropic, and other model provider APIs
patched
Critical
PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391·
PPOM for WooCommerce (woocommerce-product-addon plugin)
patched
Critical
Django QuerySet/Q Object SQL Injection via `_connector` Kwarg (CVE-2025-64459)
CVE-2025-64459·
Django ORM (QuerySet.filter() / Q object construction)
patched
Critical
"Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
CVE-2025-65354·
PHP-based "Grocery" web application, Grocery/search_products_itname.php endpoint
unpatched
High
ZoneMinder — Second-Order SQL Injection via Event Rename (CVE-2026-27470)
CVE-2026-27470·
ZoneMinder
patched
Critical
WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379
CVE-2026-6379·
WordPress plugin "WP Photo Album Plus" (WPPA+) by opajaap
patched
Critical
WordPress "Form Maker" Plugin Unauthenticated SQL Injection — CVE-2026-3359
CVE-2026-3359·
WordPress "Form Maker" plugin by Web10
unpatched
High
WeGIA Authenticated Error-Based SQL Injection Exploitation Helper (CVE-2026-23723)
CVE-2026-23723 / GHSA-xfmp-2hf9-gfjp·
WeGIA (Web Gestão Integrada de Associações)
unpatched
High
SonicWall SMA 8200v Cross-Parameter Blind SQL Injection to Root (CVE-2026-4112)
CVE-2026-4112 (SonicWall Advisory SNWLID-2026-0003)·
SonicWall SMA 8200v management console (Jetty + Struts 2, port 8443)
unpatched
Critical
Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 (GHSA-xxh2-68g9-8jqr)·
Ormar (async Python ORM, commonly used with FastAPI/Starlette)
patched
High
OpenSTAManager Scadenzario Bulk Operations Error-Based SQL Injection — CVE-2026-24418
CVE-2026-24418·
OpenSTAManager (devcode-it/openstamanager)
patched
High
OpenSTAManager Prima Nota Error-Based SQL Injection — CVE-2026-24419
CVE-2026-24419·
OpenSTAManager (devcode-it/openstamanager)
patched
High
OpenSTAManager Global Search Amplified Time-Based Blind SQL Injection — CVE-2026-24417
CVE-2026-24417·
OpenSTAManager (devcode-it/openstamanager)
patched
High
OpenSTAManager Article Pricing Time-Based Blind SQL Injection — CVE-2026-24416
CVE-2026-24416·
OpenSTAManager (devcode-it/openstamanager)
patched
High
MikroORM Custom Type Raw SQL Injection (CVE-2026-34220)
CVE-2026-34220·
MikroORM (Node.js/TypeScript ORM)
patched
Critical
JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
CVE-2026-49048 (Advisory ID JOOMCCK-2026-001)·
JoomCCK (com_joomcck) — Content Construction Kit extension for Joomla, by JoomCoder
unpatched
High
JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
CVE-2026-49079·
JetSearch plugin for WordPress
unpatched
High
ITFlow Time-Based Blind SQL Injection via agent/ajax.php expires Parameter (CVE-2026-54597)
CVE-2026-54597·
ITFlow (open-source MSP/IT management platform)
unpatched
High
ITFlow SQL Injection via recurring_invoice_frequency (CVE-2026-54596)
CVE-2026-54596·
ITFlow (open-source MSP/IT management platform)
unpatched
Critical
Ghost CMS Content API — Unauthenticated Blind SQL Injection (CVE-2026-26980)
CVE-2026-26980·
Ghost CMS
patched
Critical
EGroupware Nextmatch Filter Authenticated SQL Injection (CVE-2026-22243)
CVE-2026-22243·
EGroupware (groupware/collaboration suite)
patched
High
Django GIS RasterField SQL Injection (CVE-2026-1207)
CVE-2026-1207·
Django django.contrib.gis (GeoDjango) RasterField queries
unpatched
High
Dagster Database I/O Manager SQL Injection via Dynamic Partition Keys (CVE-2026-41490)
CVE-2026-41490 (GHSA-mjw2-v2hm-wj34)·
Dagster database I/O manager integrations: dagster-duckdb, dagster-snowflake, dagster-gcp (BigQuery), dagster-deltalake, dagster-snowflake-polars
patched
Critical
CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)
CVE-2026-37749·
CodeAstro Simple Attendance Management System 1.0
unpatched
Critical
Centreon Multi-Vector RCE — Path Traversal, Command Injection & Blind SQLi (CVE-2026-2749)
CVE-2026-2749 (bundled with related CVE-2026-2750, CVE-2026-2751)·
Centreon (open-source IT infrastructure monitoring platform)
patched
Critical
ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
CVE-2026-5076 (chained with CVE-2026-5073, CVE-2026-5074)·
ARMember – Membership Plugin & Content Restriction (WordPress plugin)
patched
Medium
Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980
CVE-2026-23980·
Apache Superset
patched