Search Results (21105 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-45871 2026-10-07 8.1 High
LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via crafted workflow template name.
CVE-2026-102098 2 Accellion, Kiteworks 2 Kiteworks, Core 2026-10-07 7.2 High
Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function.
CVE-2026-18137 2 Ibm, Redhat 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift 2026-10-07 8.1 High
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.
CVE-2026-18180 2 Ibm, Redhat 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift 2026-10-07 6.5 Medium
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection.
CVE-2026-42708 2026-10-07 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows Blind SQL Injection.This issue affects WP Post Author: from n/a through 4.0.0.
CVE-2026-42710 2026-10-07 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Slider by 10Web slider-wd allows Blind SQL Injection.This issue affects Slider by 10Web: from n/a through 1.2.63.
CVE-2026-103668 2026-10-07 N/A
An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.
CVE-2026-42721 2026-10-07 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Blind SQL Injection.This issue affects affiliate-toolkit: from n/a through 3.9.1.
CVE-2026-42720 2026-10-07 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sarah Giles Dynamic User Directory dynamic-user-directory allows Blind SQL Injection.This issue affects Dynamic User Directory: from n/a through 2.4.
CVE-2026-42713 2026-10-07 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopiplus Post title marquee scroll post-title-marquee-scroll allows Blind SQL Injection.This issue affects Post title marquee scroll: from n/a through 9.9.
CVE-2026-42714 2026-10-07 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Piggly Dev Pix por Piggly (para Woocommerce) pix-por-piggly allows Blind SQL Injection.This issue affects Pix por Piggly (para Woocommerce): from n/a through 2.1.2.
CVE-2026-104953 2026-10-07 6.8 Medium
The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes.
CVE-2026-104667 2026-10-07 6.8 Medium
The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.
CVE-2026-107103 1 Manacle Technologies 1 Multi-tenant Erp System 2026-10-07 N/A
This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted input to the vulnerable endpoint. Successful exploitation of this vulnerability could allow the attacker to perform SQL injection attacks on the targeted system.
CVE-2026-88416 1 Mcms 1 Mcms 2026-10-07 9.8 Critical
MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature.
CVE-2026-102782 2026-10-07 N/A
Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass with no authentication or access control check of any kind. The handler reads a login request parameter through Joomla’s generic, non-sanitizing input filter, which strips HTML/script tags but never touches quotes or SQL syntax, and concatenates it directly into a query string with no escaping or parameterization:
CVE-2026-88397 2026-10-07 6.5 Medium
ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list endpoint GET /admin/User/getUsers via the gid parameter.
CVE-2026-88424 2026-10-07 9.8 Critical
FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements.
CVE-2026-56097 2 Redhat, Theforeman 4 Satellite, Satellite Capsule, Satellite Utils and 1 more 2026-10-07 6.5 Medium
A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the create_personal_access_tokens permission, even if the user access is restricted, with no Organization or Location assigned.
CVE-2026-105845 1 Payloadcms 1 Payload 2026-10-07 9.8 Critical
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.