Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Ultimate Member MEDIUM 6.5
CVE-2024-12276

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Fix: 2.10.0+
Fix from $1,600 2025-02-21
Events Manager HIGH 7.5
CVE-2024-11260

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status para…

Fix: 6.6.4+
Fix from $1,950 2025-02-21
Pinpoint Booking System MEDIUM 6.5
CVE-2024-13235

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all ver…

Fix: after 2.9.9.5.2
Fix from $1,600 2025-02-21
Wegia CRITICAL 9.8
CVE-2025-27096

WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnerability was discovered in the WeGIA application, p…

Fix: 3.2.14+
Fix from $2,300 2025-02-20
Nagios Xi MEDIUM 6.5
CVE-2024-54960

A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab comp…

Mitigation only
Fix from $1,600 2025-02-20
Pdf Manager MEDIUM 6.5
CVE-2025-0866

The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter in all versions up to, and inc…

Fix: after 1.2.2
Fix from $1,600 2025-02-20
Ltl Freight Quotes HIGH 7.5
CVE-2024-13476

The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to SQL Injection via the 'engtz_wd_save_dropship' AJAX endpoint in al…

Fix: 2.3.12+
Fix from $1,950 2025-02-20
Unclassified HIGH 7.3
CVE-2025-1464

A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204. This issue affects some unkn…

Mitigation only
Fix from $1,950 2025-02-19
Ltl Freight Quotes HIGH 7.5
CVE-2024-13485

The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters …

Fix: 3.3.8+
Fix from $1,950 2025-02-19
Small Package Quotes HIGH 7.5
CVE-2024-13491

The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parame…

Fix: 4.3.2+
Fix from $1,950 2025-02-19
Small Package Quotes HIGH 7.5
CVE-2024-13533

The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and in…

Fix: 1.3.6+
Fix from $1,950 2025-02-19
Small Package Quotes HIGH 7.5
CVE-2024-13534

The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' par…

Fix: 5.2.19+
Fix from $1,950 2025-02-19
Ltl Freight Quotes HIGH 7.5
CVE-2024-13479

The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all …

Fix: 3.2.5+
Fix from $1,950 2025-02-19
Ltl Freight Quotes HIGH 7.5
CVE-2024-13481

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters…

Fix: 3.3.5+
Fix from $1,950 2025-02-19
Ltl Freight Quotes HIGH 7.5
CVE-2024-13483

The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all …

Fix: 2.2.11+
Fix from $1,950 2025-02-19
Ltl Freight Quotes HIGH 7.5
CVE-2024-13478

The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in al…

Fix: 3.6.5+
Fix from $1,950 2025-02-19
Ltl Freight Quotes HIGH 7.5
CVE-2024-13489

The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters…

Fix: 4.2.11+
Fix from $1,950 2025-02-19
Churchcrm HIGH 8.8
CVE-2025-1132

A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The para…

Fix: after 5.13.0
Fix from $1,950 2025-02-19
Churchcrm HIGH 7.2
CVE-2025-1133

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL…

Fix: after 5.13.0
Fix from $1,950 2025-02-19
Churchcrm HIGH 7.2
CVE-2025-1134

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-…

Fix: after 5.13.0
Fix from $1,950 2025-02-19
Churchcrm HIGH 7.2
CVE-2025-1135

A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time…

Fix: after 5.13.0
Fix from $1,950 2025-02-19
Unclassified MEDIUM 6.5
CVE-2024-13676

The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'image_gallery' shortcode in all …

Mitigation only
Fix from $1,600 2025-02-19
Wegia CRITICAL 9.8
CVE-2025-26617

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.14+
Fix from $2,300 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26609

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26610

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26611

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26612

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18
Wegia HIGH 8.8
CVE-2025-26614

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.14+
Fix from $1,950 2025-02-18
Wegia HIGH 8.8
CVE-2025-26605

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $1,950 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26606

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18