Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-02-19 | CVE-2024-13676 | The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'image_gallery' shortcode in all versions up to, and including, 2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-02-19 | CVE-2024-13712 | SQL Injection vulnerability in Bin-Co Pollin The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 4.9 |
2025-02-18 | CVE-2025-26610 | SQL Injection vulnerability in Wegia WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 9.8 |
2025-02-18 | CVE-2025-26612 | SQL Injection vulnerability in Wegia WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 9.8 |
2025-02-18 | CVE-2025-26614 | SQL Injection vulnerability in Wegia 3.2.13 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 8.8 |
2025-02-18 | CVE-2024-13369 | SQL Injection vulnerability in Goodlayers Tour Master The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 8.8 |
2025-02-18 | CVE-2025-1023 | SQL Injection vulnerability in Churchcrm A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. | 9.8 |
2025-02-18 | CVE-2024-13595 | SQL Injection vulnerability in Modalsurvey Simple Signup Form The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, and including, 1.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-02-17 | CVE-2025-1389 | Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents. | 8.8 |
2025-02-17 | CVE-2025-1374 | SQL Injection vulnerability in Fabianros Real Estate Property Management System 1.0 A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. | 7.5 |