Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2025-02-19 CVE-2024-13676 The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'image_gallery' shortcode in all versions up to, and including, 2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
CWE-89
6.5
2025-02-19 CVE-2024-13712 SQL Injection vulnerability in Bin-Co Pollin
The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
bin-co CWE-89
4.9
2025-02-18 CVE-2025-26610 SQL Injection vulnerability in Wegia
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.
network
low complexity
wegia CWE-89
critical
9.8
2025-02-18 CVE-2025-26612 SQL Injection vulnerability in Wegia
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.
network
low complexity
wegia CWE-89
critical
9.8
2025-02-18 CVE-2025-26614 SQL Injection vulnerability in Wegia 3.2.13
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.
network
low complexity
wegia CWE-89
8.8
2025-02-18 CVE-2024-13369 SQL Injection vulnerability in Goodlayers Tour Master
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
goodlayers CWE-89
8.8
2025-02-18 CVE-2025-1023 SQL Injection vulnerability in Churchcrm
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality.
network
low complexity
churchcrm CWE-89
critical
9.8
2025-02-18 CVE-2024-13595 SQL Injection vulnerability in Modalsurvey Simple Signup Form
The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, and including, 1.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
modalsurvey CWE-89
6.5
2025-02-17 CVE-2025-1389 Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.
network
low complexity
CWE-89
8.8
2025-02-17 CVE-2025-1374 SQL Injection vulnerability in Fabianros Real Estate Property Management System 1.0
A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0.
network
low complexity
fabianros CWE-89
7.5