Total
20691 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-25757 | 1 Wdmtech | 1 Vwishlist | 2026-08-21 | N/A | 7.1 HIGH |
| Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid parameters. Attackers can send POST requests to the component with crafted SQL payloads in these parameters to extract sensitive database information including version and database names. | |||||
| CVE-2019-25756 | 1 Wdmtech | 1 Vaccount | 2026-08-21 | N/A | 8.2 HIGH |
| Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. Attackers can send GET requests to the vaccount-dashboard/expense endpoint with crafted SQL payloads in the vid parameter to extract sensitive database information including version and database names. | |||||
| CVE-2019-25755 | 1 Wdmtech | 1 Vreview | 2026-08-21 | N/A | 8.2 HIGH |
| Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter. Attackers can send POST requests to the editReview task endpoint with URL-encoded SQL UNION statements in the cmId parameter to extract database information including usernames, passwords, and database versions. | |||||
| CVE-2019-25754 | 1 Wdmtech | 1 Vrestaurant | 2026-08-21 | N/A | 8.2 HIGH |
| Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch parameter. Attackers can send POST requests to the menu-listing-layout endpoint with crafted SQL payloads in the keysearch parameter to extract database table names and sensitive information from the database. | |||||
| CVE-2017-20271 | 1 Nordmograph | 1 Streetguessr Game | 2026-08-21 | N/A | 8.2 HIGH |
| Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with the option=com_streetguess&view=maps parameters and inject SQL code in the catid parameter to extract sensitive database information including version and database names. | |||||
| CVE-2017-20270 | 1 Raindropsinfotech | 1 Twitch Tv | 2026-08-21 | N/A | 8.2 HIGH |
| Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET requests to index.php with option=com_twitchtv and view parameters containing SQL injection payloads to extract sensitive database information including credentials and configuration data. | |||||
| CVE-2017-20269 | 1 Terrywcarter | 1 Kissgallery | 2026-08-21 | N/A | 8.2 HIGH |
| Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and extract sensitive information. | |||||
| CVE-2017-20268 | 1 Zcontent | 1 Zap Calendar Lite | 2026-08-21 | N/A | 8.2 HIGH |
| Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with crafted SQL payloads to extract sensitive database information including database names and table structures. | |||||
| CVE-2026-17227 | 1 Ibm | 1 Db2 Mirror For I | 2026-08-21 | N/A | 5.4 MEDIUM |
| IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command. | |||||
| CVE-2026-76783 | 2026-08-20 | 7.5 HIGH | 7.3 HIGH | ||
| A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. | |||||
| CVE-2026-68566 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | |||||
| CVE-2026-66649 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. | |||||
| CVE-2026-66593 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. | |||||
| CVE-2025-15688 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Capella <= 2.5.5 versions. | |||||
| CVE-2026-76785 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument orderBy/orderFormat results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-74013 | 2026-08-20 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. | |||||
| CVE-2026-73185 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. | |||||
| CVE-2026-66680 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. | |||||
| CVE-2026-66668 | 2026-08-20 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. | |||||
| CVE-2026-66609 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | |||||
