148 vulnerabilidades · Database · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-8522
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Database Windows ⚡ nuclei
10.0
CRITICAL
EPSS
88.1%
2024 CWE-89 2 PoCs

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-24786
whodb Database ⚡ nuclei
10.0
CRITICAL
EPSS
51.8%
2025 CWE-35 0 PoCs

WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no path traversal prevention in place. This allows an unauthenticated attacker to open any Sqlite3 database present on the host machine that the application is running on. Affected versions of WhoDB allow users to connect to Sqlite3 databases. By default, the databases must be present in `/db/` (or alternatively `./tmp/` if development mode is enabled). If no databases are present in the default directory, the UI indicates that the user is unable to

CVE-2024-51482
zoneminder Web Database ⚡ nuclei
10.0
CRITICAL
EPSS
50.9%
2024 CWE-89 1 PoC

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.

CVE-2024-36412
SuiteCRM Database ⚡ nuclei
10.0
CRITICAL
EPSS
93.6%
2024 CWE-89 0 PoCs

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

CVE-2024-7854
Woo Inquiry Web Database Windows ⚡ nuclei
10.0
CRITICAL
EPSS
80.3%
2024 CWE-89 1 PoC

The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to insufficient escaping on the user supplied parameter 'dbid' and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-8529
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Database Windows ⚡ nuclei
10.0
CRITICAL
EPSS
71.8%
2024 CWE-89 2 PoCs

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-3922
Dokan Pro Web Database Windows ⚡ nuclei
10.0
CRITICAL
EPSS
89.7%
2024 CWE-89 1 PoC

The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-51567
🔥 KEV Software Genérico Database ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 5 PoCs

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.

CVE-2024-3605
WP Hotel Booking Web Database Windows ⚡ nuclei
10.0
CRITICAL
EPSS
81.4%
2024 CWE-89 1 PoC

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2022-44588
Cryptocurrency Widgets Pack Web Database Windows ⚡ nuclei
9.9
CRITICAL
EPSS
34.7%
2022 CWE-89 0 PoCs

Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.

CVE-2022-45808
LearnPress – WordPress LMS Plugin Web Database Windows ⚡ nuclei
9.9
CRITICAL
EPSS
83.6%
2022 CWE-89 1 PoC

SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

CVE-2025-58443
fogproject Database ⚡ nuclei
9.9
CRITICAL
EPSS
11.0%
2025 CWE-306 2 PoCs

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to perform an unauthenticated DB dump where they could pull a full SQL DB without credentials. A fix is expected to be released 9/15/2025. To address this vulnerability immediately, upgrade to the latest version of either the dev-branch or working-1.6 branch. This will patch the issue for users concerned about immediate exposure. See the FOG Project documentation for step-by-step upgrade instructions: h

CVE-2024-27956
Automatic Database ⚡ nuclei
9.9
CRITICAL
EPSS
93.8%
2024 CWE-89 17 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.

CVE-2023-27034
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
90.5%
2023 1 PoC

PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.

CVE-2023-34752
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
30.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

CVE-2023-6567
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
82.3%
2023 CWE-89 1 PoC

The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-23488
Paid Memberships Pro WordPress Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
84.2%
2023 5 PoCs

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.

CVE-2023-34753
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
33.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.

CVE-2023-5204
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
87.0%
2023 CWE-89 2 PoCs

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-47253
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2023 4 PoCs

Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.