Export limit exceeded: 19519 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (19519 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2017-20279 1 Extensions 1 Joomla Payage 2026-06-22 8.2 High
Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers can send GET requests to index.php with malicious aid values in the make_payment task to extract sensitive database information using boolean-based blind or time-based blind techniques.
CVE-2017-20273 1 Joomlashowroom 1 Event Registration Pro Calendar 2026-06-22 8.2 High
Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registrationpro&view=category&id parameter containing SQL injection payloads to extract sensitive database information.
CVE-2017-20267 1 Joomlathat 1 Calendar Planner 2026-06-22 8.2 High
Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitive database information.
CVE-2019-25756 1 Wdmtech 1 Vaccount 2026-06-22 8.2 High
Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. Attackers can send GET requests to the vaccount-dashboard/expense endpoint with crafted SQL payloads in the vid parameter to extract sensitive database information including version and database names.
CVE-2019-25750 1 Cmsjunkie 1 Multiplehotelreservation 2026-06-22 8.2 High
Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hotel_id parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL UNION SELECT statements to extract sensitive database information including table names and column data.
CVE-2026-12789 1 Ilias 1 Learning Management System 2026-06-22 4.7 Medium
A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::executeQueries of the file components/ILIAS/Tracking/classes/class.ilTrQuery.php of the component Learning Progress Tracking. Such manipulation of the argument troup_table_nav leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-39438 2 Emraan Cheema, Wordpress 2 Listingpro, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.
CVE-2026-49080 2 Tms, Wordpress 2 Wpdatatables, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.
CVE-2025-69135 2 Curlythemes, Wordpress 2 Events Schedule - Wordpress Events Calendar Plugin, Wordpress 2026-06-20 8.5 High
Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.
CVE-2026-22335 2 Wc Lovers., Wordpress 2 Woocommerce Frontend Manager – Ultimate, Wordpress 2026-06-20 8.5 High
Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.
CVE-2026-22340 2 Jobster Marketplace, Wordpress 2 Wpjobster, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.
CVE-2026-48875 2 Jetimpex Inc., Wordpress 2 Jetsmartfilters, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.
CVE-2026-49076 2 Jetimpex Inc., Wordpress 2 Jetengine, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.
CVE-2026-49079 2 Jetimpex Inc., Wordpress 2 Jetsearch, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.
CVE-2026-49084 2 Jetimpex Inc., Wordpress 2 Jetengine, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.
CVE-2026-54185 2 Themeco, Wordpress 2 Cornerstone, Wordpress 2026-06-20 8.5 High
Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
CVE-2026-54187 2 Jetimpex Inc., Wordpress 2 Jetengine, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
CVE-2025-59554 2 Advanced Ads Gmbh, Wordpress 2 Advanced Ads – Tracking, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
CVE-2026-54819 2 Webilia Inc., Wordpress 2 Listdom, Wordpress 2026-06-20 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.
CVE-2026-54815 2 Cargo Rd, Wordpress 2 Cargo Shipping Location For Woocommerce, Wordpress 2026-06-20 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.