Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Wegia CRITICAL 9.8
CVE-2025-26607

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26608

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18
Unclassified HIGH 8.5
CVE-2025-22639

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn Distance Rate Shipping for WooCommerc…

Mitigation only
Fix from $1,950 2025-02-18
Unclassified CRITICAL 9.8
CVE-2024-55460

A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attacke…

Mitigation only
Fix from $2,300 2025-02-18
Unclassified MEDIUM 6.7
CVE-2025-22207

Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.

Mitigation only
Fix from $1,600 2025-02-18
Tour Master HIGH 8.8
CVE-2024-13369

The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all ver…

Fix: 5.3.8+
Fix from $1,950 2025-02-18
Churchcrm CRITICAL 9.8
CVE-2025-1023

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL In…

Fix: after 5.13.0
Fix from $2,300 2025-02-18
Simple Signup Form MEDIUM 6.5
CVE-2024-13595

The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, and i…

Fix: after 1.6.5
Fix from $1,600 2025-02-18
Luxcal Web Calendar CRITICAL 9.8
CVE-2025-25221

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If t…

Fix: 5.3.3l / 5.3.3m+
Fix from $2,300 2025-02-18
Luxcal Web Calendar CRITICAL 9.8
CVE-2025-25222

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php.…

Fix: 5.3.3l / 5.3.3m+
Fix from $2,300 2025-02-18
Real Estate Property Management System HIGH 7.5
CVE-2025-1381

A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been classified as critical. This affects an unknown pa…

No fix yet
Fix from $1,950 2025-02-17
Real Estate Property Management System CRITICAL 9.8
CVE-2025-1379

A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. Affected by this vulnerability…

No fix yet
Fix from $2,300 2025-02-17
Gym Management System CRITICAL 9.8
CVE-2025-1380

A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of t…

No fix yet
Fix from $2,300 2025-02-17
Themes Coder HIGH 8.6
CVE-2024-13726

The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action av…

Fix: after 1.3.4
Fix from $1,950 2025-02-17
Orca Hcm HIGH 8.8
CVE-2025-1389

Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read…

Fix: 11.0+
Fix from $1,950 2025-02-17
Real Estate Property Management System HIGH 7.5
CVE-2025-1374

A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of th…

No fix yet
Fix from $1,950 2025-02-17
Unclassified HIGH 7.6
CVE-2025-26755

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Airbnb Review Slider wp-airbnb-rev…

Mitigation only
Fix from $1,950 2025-02-16
Unclassified CRITICAL 9.3
CVE-2025-22290

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology LTL Freight Quotes – FreightQ…

Mitigation only
Fix from $2,300 2025-02-16
Library Card System HIGH 7.5
CVE-2025-1356

A vulnerability was found in needyamin Library Card System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality o…

No fix yet
Fix from $1,950 2025-02-16
Ltl Freight Quotes HIGH 7.5
CVE-2024-13488

The LTL Freight Quotes – Estes Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all…

Fix: 3.3.8+
Fix from $1,950 2025-02-15
Wp Project Manager MEDIUM 6.5
CVE-2024-13500

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time…

Fix: 2.6.18+
Fix from $1,600 2025-02-15
Online Shopping Portal Project HIGH 8.8
CVE-2025-26156

A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to exe…

No fix yet
Fix from $1,950 2025-02-14
Beauty Parlour Management System MEDIUM 5.9
CVE-2025-26157

A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote atta…

No fix yet
Fix from $1,600 2025-02-14
Hoosk MEDIUM 5.1
CVE-2025-25991

SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.

No fix yet
Fix from $1,600 2025-02-14
Feminer Wms MEDIUM 5.1
CVE-2025-25992

SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.

No fix yet
Fix from $1,600 2025-02-14
Feminer Wms MEDIUM 5.1
CVE-2025-25993

SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."

No fix yet
Fix from $1,600 2025-02-14
Feminer Wms HIGH 7.5
CVE-2025-25994

SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id.

No fix yet
Fix from $1,950 2025-02-14
Elabftw HIGH 8.8
CVE-2025-25206

eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authentica…

Fix: 5.1.15+
Fix from $1,950 2025-02-14
Unclassified CRITICAL 10.0
CVE-2024-13152

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring …

Mitigation only
Fix from $2,300 2025-02-14
Bit Assist MEDIUM 6.5
CVE-2025-0821

Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to i…

Fix: 1.5.3+
Fix from $1,600 2025-02-14