2231 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2026-41460
SocialEngine Database
9.3
CRITICAL
EPSS
0.4%
2026 CWE-89 3 PoCs

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary data from the database, reset administrator account passwords, and gain unauthorized access to the Packages Manager in the Admin Panel, potentially enabling remote code execution.

CVE-2026-28516
openDCIM DevOps Web Database
9.3
CRITICAL
EPSS
23.8%
2026 CWE-89 1 PoC

openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitation. An authenticated user can execute arbitrary SQL statements against the underlying database.

CVE-2026-27743
referer_spam Database
9.3
CRITICAL
EPSS
0.2%
2026 CWE-89 2 PoCs

The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_spam_supprimer action handlers. The handlers read the url parameter from a GET request and interpolate it directly into SQL LIKE clauses without input validation or parameterization. The endpoints do not enforce authorization checks and do not use SPIP action protections such as securiser_action(), allowing remote attackers to execute arbitrary SQL queries.

CVE-2023-53960
Impact/Pulse/First Web Database
9.3
CRITICAL
EPSS
0.3%
2023 CWE-89 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized access to the system.

CVE-2023-32590
Subscribe to Category Database ⚡ nuclei
9.3
CRITICAL
EPSS
19.3%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category.This issue affects Subscribe to Category: from n/a through 2.7.4.

CVE-2023-50839
JS Help Desk – Best Help Desk & Support Plugin Database ⚡ nuclei
9.3
CRITICAL
EPSS
16.3%
2023 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.1.

CVE-2023-53975
Atom CMS Web Database
9.3
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

CVE-2023-53877
Bus Reservation System Database
9.3
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.

CVE-2023-53982
PMB Web Database
9.3
CRITICAL
EPSS
0.0%
2023 CWE-89 1 PoC

PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.

CVE-2023-53972
WebTareas Database
9.3
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

WebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate database queries. Attackers can exploit error-based and time-based blind SQL injection techniques to extract database information and potentially access sensitive system data.

CVE-2023-48788
🔥 KEV FortiClientEMS Networking Database
9.3
CRITICAL
EPSS
94.1%
2023 CWE-89 5 PoCs

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

CVE-2023-28787
Quiz And Survey Master Database ⚡ nuclei
9.3
CRITICAL
EPSS
32.1%
2023 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.

CVE-2024-55982
Share Buttons – Social Media Database
9.3
CRITICAL
EPSS
31.8%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through <= 1.0.2.

CVE-2024-50491
RSVP ME Database
9.3
CRITICAL
EPSS
37.7%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.

CVE-2024-13979
St. Joe ERP System ("圣乔ERP系统") Web Database ⚡ nuclei
9.3
CRITICAL
EPSS
9.0%
2024 CWE-89 2 PoCs

A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database. Successful exploitation may result in unauthorized data access, modification of records, or limited disruption of service. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundatio

CVE-2024-58307
CSZCMS Web Database
9.3
CRITICAL
EPSS
0.1%
2024 CWE-89 1 PoC

CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.

CVE-2024-43917
TI WooCommerce Wishlist Database ⚡ nuclei
9.3
CRITICAL
EPSS
90.0%
2024 CWE-89 2 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2.

CVE-2024-43144
Cost Calculator Builder Database ⚡ nuclei
9.3
CRITICAL
EPSS
23.2%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.

CVE-2024-5057
Easy Digital Downloads Database ⚡ nuclei
9.3
CRITICAL
EPSS
64.4%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.

CVE-2024-55978
Code Generator Pro Database
9.3
CRITICAL
EPSS
6.5%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WalletStation Code Generator Pro code-generator-pro allows SQL Injection.This issue affects Code Generator Pro: from n/a through <= 1.2.