Search Results (20973 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-103229 1 Adithyayelloju 1 Restaurant-management-system 2026-09-30 7.3 High
A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-102456 1 Digiwin 1 Easyflow .net 2026-09-30 6.5 Medium
EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.
CVE-2026-6806 2026-09-30 7.5 High
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-16596 2026-09-30 6.5 Medium
The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the 'data_fields_list' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-100847 1 Azuracast 1 Azuracast 2026-09-30 7.5 High
AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings.
CVE-2026-103231 1 Adithyayelloju 1 Restaurant-management-system 2026-09-30 7.3 High
A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-102578 1 Moodle 1 Moodle 2026-09-30 5.5 Medium
A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.
CVE-2026-76570 2026-09-30 N/A
Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.
CVE-2026-97293 2026-09-30 8.5 High
Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
CVE-2026-96828 2026-09-30 7.6 High
Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.
CVE-2026-96827 2026-09-30 7.6 High
Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.
CVE-2026-96822 2026-09-30 9.3 Critical
Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.
CVE-2026-96346 2026-09-30 7.6 High
Author SQL Injection in WP ERP <= 1.17.9 versions.
CVE-2026-96345 2026-09-30 7.6 High
Administrator SQL Injection in Estatik <= 4.3.5 versions.
CVE-2026-94177 2026-09-30 8.5 High
Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.
CVE-2026-94115 2026-09-30 8.5 High
Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.
CVE-2026-94082 2026-09-30 7.6 High
Author SQL Injection in Quiz Cat <= 3.1.1 versions.
CVE-2026-93621 2026-09-30 8.2 High
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
CVE-2026-62085 2026-09-30 7.6 High
Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.
CVE-2026-103117 1 Os4ed 1 Opensis-classic 2026-09-30 4.7 Medium
A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.