Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.3 CVE-2026-54819 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54808 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Bli… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54809 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. … Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2025-59554 Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54811 Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54187 Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. Mitigation only Fix from $2,3002026-06-17 HIGH 8.5 CVE-2026-54185 Subscriber SQL Injection in Cornerstone < 7.8.8 versions. Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.3 CVE-2026-54186 Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-49080 Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-49084 Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. Mitigation only Fix from $2,3002026-06-17 HIGH 8.5 CVE-2026-49073 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Inje… Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.3 CVE-2026-49076 Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-49079 Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-48875 Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. Mitigation only Fix from $2,3002026-06-17 HIGH 8.5 CVE-2026-48967 Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions. Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.3 CVE-2026-39596 Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-39438 Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. Mitigation only Fix from $2,3002026-06-17 MEDIUM 5.5 CVE-2026-28576 In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure w… Android Mitigation only Fix from $1,6002026-06-17 CRITICAL 9.3 CVE-2026-22332 Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions. Mitigation only Fix from $2,3002026-06-17 HIGH 8.5 CVE-2026-22335 Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions. Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.3 CVE-2026-22340 Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. Mitigation only Fix from $2,3002026-06-17 HIGH 7.5 CVE-2026-12360 The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler ac… Mitigation only Fix from $1,9502026-06-17 HIGH 8.5 CVE-2025-69135 Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions. Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.3 CVE-2026-52715 Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. Mitigation only Fix from $2,3002026-06-16 CRITICAL 9.3 CVE-2026-39574 Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions. Mitigation only Fix from $2,3002026-06-16 HIGH 8.5 CVE-2026-39581 Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions. Mitigation only Fix from $1,9502026-06-16 CRITICAL 9.3 CVE-2026-49772 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allo… Mitigation only Fix from $2,3002026-06-16 HIGH 7.6 CVE-2026-52712 Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions. Mitigation only Fix from $1,9502026-06-16 HIGH 8.8 CVE-2026-8444 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in… Mitigation only Fix from $1,9502026-06-16 HIGH 8.8 CVE-2026-8443 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_ch… Mitigation only Fix from $1,9502026-06-16