Total
20690 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-3430 | 2026-08-26 | N/A | 8.6 HIGH | ||
| The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. | |||||
| CVE-2026-16539 | 2026-08-26 | N/A | 8.1 HIGH | ||
| The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks. | |||||
| CVE-2026-12713 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004. | |||||
| CVE-2026-17017 | 2026-08-26 | N/A | 8.1 HIGH | ||
| The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks. | |||||
| CVE-2026-18473 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | |||||
| CVE-2026-16977 | 2026-08-26 | N/A | 8.1 HIGH | ||
| The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection. | |||||
| CVE-2026-16959 | 2026-08-26 | N/A | 6.8 MEDIUM | ||
| The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection. | |||||
| CVE-2026-16950 | 2026-08-26 | N/A | 8.6 HIGH | ||
| The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks. | |||||
| CVE-2026-18057 | 2026-08-26 | N/A | 8.1 HIGH | ||
| The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people. | |||||
| CVE-2026-19094 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restrict which template file a request may load, allowing unauthenticated users to inject SQL and to read question and answer content belonging to courses that are not publicly available. The injected text reaches the query as grammar rather than as data, and on the database engines tested it does not yield extraction of arbitrary data, so the confidentiality impact is the disclosed course content rather than the database at large. | |||||
| CVE-2026-12983 | 2026-08-26 | N/A | 8.6 HIGH | ||
| The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data. | |||||
| CVE-2026-18230 | 2026-08-26 | N/A | 8.1 HIGH | ||
| The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL injection attacks. | |||||
| CVE-2026-19053 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection. | |||||
| CVE-2026-18666 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including user password hashes. | |||||
| CVE-2026-14601 | 2026-08-26 | N/A | 6.8 MEDIUM | ||
| The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks. | |||||
| CVE-2026-13613 | 2026-08-26 | N/A | 8.8 HIGH | ||
| The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection. | |||||
| CVE-2026-15205 | 2026-08-26 | N/A | 8.6 HIGH | ||
| The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user credentials and other secrets — through both in-band (reflected) and time-based blind extraction. | |||||
| CVE-2026-18474 | 2026-08-26 | N/A | 8.6 HIGH | ||
| The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured. | |||||
| CVE-2026-19049 | 2026-08-26 | N/A | 8.6 HIGH | ||
| The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores. | |||||
| CVE-2026-18653 | 2026-08-26 | N/A | 7.2 HIGH | ||
| The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not otherwise able to reach. | |||||
