Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.5
CVE-2026-2232

The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in …

Mitigation only
Fix from $1,950 2026-02-19
Unclassified HIGH 7.5
CVE-2026-1581

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.1…

Mitigation only
Fix from $1,950 2026-02-19
Worktime HIGH 8.8
CVE-2025-15560

An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If…

Fix: after 11.8.8
Fix from $1,950 2026-02-19
Unclassified HIGH 7.6
CVE-2026-25418

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified HIGH 7.6
CVE-2026-25378

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testin…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified HIGH 7.6
CVE-2026-23805

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media Search Enhanced media-search-…

Mitigation only
Fix from $1,950 2026-02-19
Patient Record Management System HIGH 7.5
CVE-2026-2706

A flaw has been found in code-projects Patient Record Management System 1.0. This affects an unknown function of the file /fecalysis_not.php. This ma…

No fix yet
Fix from $1,950 2026-02-19
Event Management System CRITICAL 9.8
CVE-2026-2689

A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The …

Mitigation only
Fix from $2,300 2026-02-19
Event Management System CRITICAL 9.8
CVE-2026-2690

A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax…

Mitigation only
Fix from $2,300 2026-02-19
Event Management System CRITICAL 9.8
CVE-2026-2691

A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/m…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified MEDIUM 6.5
CVE-2026-0722

The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified HIGH 7.5
CVE-2025-12707

The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified MEDIUM 6.7
CVE-2025-15585

Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file search function. Successful exploi…

Mitigation only
Fix from $1,600 2026-02-19
Electronic Archives System CRITICAL 9.8
CVE-2026-2682

A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /…

Fix: after 3.2.210802
Fix from $2,300 2026-02-18
Unclassified MEDIUM 5.3
CVE-2025-12812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service. Rem…

No fix yet
Fix from $1,600 2026-02-18
Majordomo CRITICAL 9.8
CVE-2026-27179

MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. The commands_search.inc.php fil…

Patch available
Fix from $2,300 2026-02-18
Unclassified MEDIUM 6.3
CVE-2026-2663

A security vulnerability has been detected in Alixhan xh-admin-backend up to 1.7.0. This issue affects some unknown processing of the file /frontend-…

Mitigation only
Fix from $1,600 2026-02-18
Scholars Tracking System CRITICAL 9.8
CVE-2025-70152

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.p…

Mitigation only
Fix from $2,300 2026-02-18
Membership Management System CRITICAL 9.8
CVE-2025-70149

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

Mitigation only
Fix from $2,300 2026-02-18
Unclassified HIGH 8.6
CVE-2025-59920

When hours are entered in time@work, version 7.0.5, it performs a query to display the projects assigned to the user. If the query URL is copied and …

Mitigation only
Fix from $1,950 2026-02-18
Unclassified MEDIUM 6.5
CVE-2026-1317

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.3…

Mitigation only
Fix from $1,600 2026-02-18
Unclassified HIGH 7.5
CVE-2026-2495

The WPNakama – Team and multi-Client Collaboration, Editorial and Project Management plugin for WordPress is vulnerable to SQL Injection via the 'ord…

Mitigation only
Fix from $1,950 2026-02-18
Unclassified MEDIUM 6.5
CVE-2026-1639

The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order'…

Mitigation only
Fix from $1,600 2026-02-18
Unclassified HIGH 7.5
CVE-2026-2576

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'paymen…

Mitigation only
Fix from $1,950 2026-02-18
Unclassified HIGH 7.3
CVE-2026-2621

A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This affects an unknown part of the…

Mitigation only
Fix from $1,950 2026-02-17
Unclassified HIGH 7.3
CVE-2026-2620

A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown functionality of the file /We…

Mitigation only
Fix from $1,950 2026-02-17
Jorani HIGH 7.6
CVE-2025-67102

A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands vi…

Fix: after 1.0.4
Fix from $1,950 2026-02-17
Student Management System HIGH 8.8
CVE-2024-55270

phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.

No fix yet
Fix from $1,950 2026-02-17
Jizhicms HIGH 7.2
CVE-2025-70397

jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

No fix yet
Fix from $1,950 2026-02-17
Unclassified HIGH 8.6
CVE-2025-7631

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Technologies Software Informati…

Mitigation only
Fix from $1,950 2026-02-17