Vulnerabilities (CVE)

Filtered by CWE-89
Total 20012 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-49076 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.
CVE-2026-48967 2026-06-17 N/A 8.5 HIGH
Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.
CVE-2026-22332 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.
CVE-2025-59554 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
CVE-2026-28576 1 Google 1 Android 2026-06-17 N/A 5.5 MEDIUM
In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-57819 1 Sangoma 1 Freepbx 2026-06-17 N/A 9.8 CRITICAL
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.
CVE-2026-54819 2026-06-17 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.
CVE-2026-54815 2026-06-17 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.
CVE-2026-54813 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects SureDash: from n/a through 1.8.0.
CVE-2026-54811 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.
CVE-2026-54808 2026-06-17 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.
CVE-2026-54187 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
CVE-2026-22335 2026-06-17 N/A 8.5 HIGH
Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.
CVE-2025-69135 2026-06-17 N/A 8.5 HIGH
Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.
CVE-2026-22340 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.
CVE-2026-49080 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.
CVE-2026-49079 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.
CVE-2026-39596 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.
CVE-2026-39438 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.
CVE-2026-54186 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.