Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.5 CVE-2026-10207 The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficie… No fix yet Fix from $1,9502026-07-28 MEDIUM 6.5 CVE-2026-15267 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_… No fix yet Fix from $1,6002026-07-28 HIGH 7.5 CVE-2026-13161 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_use… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-14516 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' para… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-12800 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-js… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-12741 The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter i… No fix yet Fix from $1,9502026-07-28 MEDIUM 6.5 CVE-2026-6251 The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5. This is due t… No fix yet Fix from $1,6002026-07-28 HIGH 7.5 CVE-2026-51077 SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_… No fix yet Fix from $1,9502026-07-27 CRITICAL 9.1 CVE-2026-17191 An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend q… No fix yet Fix from $2,3002026-07-27 CRITICAL 9.1 CVE-2025-50455 SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vuln… No fix yet Fix from $2,3002026-07-27 HIGH 7.6 CVE-2026-66427 Administrator SQL Injection in WP Google Review Slider <= 18.4 versions. No fix yet Fix from $1,9502026-07-27 CRITICAL 9.3 CVE-2026-59550 Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. No fix yet Fix from $2,3002026-07-27 HIGH 8.5 CVE-2026-59551 Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. No fix yet Fix from $1,9502026-07-27 HIGH 7.6 CVE-2026-59537 Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. No fix yet Fix from $1,9502026-07-27 CRITICAL 9.3 CVE-2026-59538 Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. No fix yet Fix from $2,3002026-07-27 CRITICAL 9.3 CVE-2026-59549 Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. No fix yet Fix from $2,3002026-07-27 CRITICAL 9.3 CVE-2026-59527 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. No fix yet Fix from $2,3002026-07-27 CRITICAL 9.3 CVE-2026-59533 Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. Mitigation only Fix from $2,3002026-07-27 CRITICAL 9.2 CVE-2026-65766 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynami… No fix yet Fix from $2,3002026-07-27 CRITICAL 9.2 CVE-2026-65876 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMo… No fix yet Fix from $2,3002026-07-27 HIGH 8.2 CVE-2026-65877 Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media … Mitigation only Fix from $1,9502026-07-27 MEDIUM 6.5 CVE-2026-65707 Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by … No fix yet Fix from $1,6002026-07-24 HIGH 7.3 CVE-2026-16765 A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/l… No fix yet Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-63359 The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-cra… Mitigation only Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-65761 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead … No fix yet Fix from $2,3002026-07-23 HIGH 7.6 CVE-2026-65532 Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. No fix yet Fix from $1,9502026-07-23 HIGH 8.5 CVE-2026-65526 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection… No fix yet Fix from $1,9502026-07-23 HIGH 7.1 CVE-2026-65494 Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. No fix yet Fix from $1,9502026-07-23 HIGH 7.6 CVE-2026-65462 Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. No fix yet Fix from $1,9502026-07-23 HIGH 8.5 CVE-2026-65450 Contributor SQL Injection in MapSVG <= 8.14.0 versions. No fix yet Fix from $1,9502026-07-23