Tag
Unauthenticated SQL Injection in Weaver E-cology
1 rule 2 TTPs 1 CVEWeaver E-cology is vulnerable to an unauthenticated SQL injection via the 'userIdentifiers' GET parameter, allowing attackers to extract sensitive database information including administrator credentials.
Authenticated Blind SQL Injection in ScadaLTS
1 rule 2 TTPs 1 CVEScadaLTS 2.8.1-rc is vulnerable to an authenticated blind SQL injection via the sortBy parameter in the /api/events/search endpoint, allowing low-privileged users to exfiltrate database contents.
SQL Injection in code-projects Matrimonial System
1 rule 1 TTP 1 CVEMatrimonial System 1.0 contains a remote SQL injection vulnerability in the search.php script, allowing unauthenticated attackers to manipulate search arguments to execute arbitrary database commands.
SQL Injection in FilePress Publish Module
1 TTP 1 CVEAn unpatched SQL injection vulnerability in zyx0814 FilePress versions 3.0.1 and earlier allows remote attackers to manipulate the orderby or order arguments within search.php.
SQL Injection in SourceCodester College Notes Gallery Management System
1 rule 2 TTPs 1 CVESourceCodester College Notes Gallery Management System version 1.0 contains a SQL injection vulnerability in the login.php file, allowing unauthenticated remote attackers to execute arbitrary database queries.
SQL Injection in itsourcecode Leave Management System
1 rule 1 TTP 1 CVEThe itsourcecode Leave Management System version 1.0 is vulnerable to remote SQL injection via the user_email parameter in login.php, enabling potential authentication bypass or unauthorized database access.
Remote SQL Injection in Feng Office Legacy API
1 rule 1 TTP 1 CVEFeng Office versions up to 3.11.13.11 are susceptible to remote SQL injection via the 'auth' parameter in the Legacy API component.
SQL Injection in Sticky Chat Widget WordPress Plugin
1 rule 1 TTP 1 CVEThe Sticky Chat Widget plugin for WordPress (<= 1.4.2) is vulnerable to unauthenticated SQL injection via the 'scw_save_form_data' AJAX action, allowing potential exfiltration of sensitive database information.
SQL Injection in Inventory Management System
1 rule 1 TTP 1 CVEA SQL injection vulnerability in the login component of inventory-management-system 1.0.0 allows remote attackers to execute arbitrary database queries via the username and password parameters.
Unauthenticated Blind SQL Injection in WP Fastest Cache
1 rule 2 TTPs 1 CVEWP Fastest Cache versions 1.2.2 and earlier contain a blind SQL injection vulnerability allowing unauthenticated attackers to exfiltrate sensitive user data via the wordpress_logged_in cookie.
SQL Injection in SourceCodester Online Voting System
3 rules 1 TTP 1 CVESourceCodester Online Voting System 1.0 is vulnerable to remote SQL injection via the 'id' parameter in the '/ajax.php?action=save_user' endpoint, enabling unauthenticated attackers to manipulate database queries.
SQL Injection in Vehicle Management System
1 rule 1 TTP 1 CVEVehicle Management System version 1.0 contains an SQL injection vulnerability in the busid parameter of /busprofile.php, allowing unauthenticated remote attackers to execute arbitrary SQL queries.
SQL Injection Vulnerability in DreamMaker
1 TTP 1 CVEAuthenticated remote attackers can exploit a SQL injection vulnerability in Interinfo's DreamMaker software to execute arbitrary database queries, leading to unauthorized data exfiltration or destruction.
SQL Injection in Doctor Appointment System 1.0
2 rules 1 TTP 1 CVEAn SQL injection vulnerability in the email parameter of the patient_login.php file allows unauthenticated remote attackers to execute arbitrary SQL commands in Doctor Appointment System 1.0.
CVE-2026-85388 SQL Injection in Worklenz
1 TTP 2 CVEsAuthenticated attackers can exploit improper validation of the sort-field parameter in Worklenz <= 3.0.0 to perform blind SQL injection against PostgreSQL backends.
SQL Injection Vulnerability in TRtek Products's Store
1 TTP 1 CVECVE-2026-18210 is a critical SQL injection vulnerability in the TRtek Products's Store application, allowing unauthenticated attackers to manipulate backend database queries.
Blind SQL Injection in EasyAppointments
1 rule 1 TTP 1 CVEEasyAppointments versions 1.5.1 and earlier contain a blind SQL injection vulnerability in search endpoints that allows authenticated attackers to extract sensitive database content via malicious 'order_by' parameters.
Blind SQL Injection Vulnerability in Payload CMS
1 rule 1 TTP 1 CVEPayload CMS versions prior to 3.73.0 are vulnerable to Blind SQL Injection via maliciously crafted JSON filter inputs processed by the Drizzle database adapter.
Unauthenticated SQL Injection in MasterStudy LMS Plugin
1 rule 1 TTP 1 CVECVE-2024-1512 is an unauthenticated union-based SQL injection vulnerability in the MasterStudy LMS WordPress plugin via the 'user' parameter, allowing remote database compromise.
SQL Injection Vulnerability in Online Shopping System
1 rule 1 TTP 1 CVEThe Online Shopping System 1.0 contains an unauthenticated SQL injection vulnerability in the search functionality of /action.php, allowing remote attackers to execute arbitrary database queries.
SQL Injection in CubeCart 6.7.4
2 rules 3 TTPsAn authenticated SQL injection vulnerability in CubeCart 6.7.4 allows administrative users to execute arbitrary SQL commands due to improper sanitization of the download_expire parameter.
WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding
7 rules 15 TTPs 1 CVEWWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.
Unauthenticated SQL Injection in WooCommerce Lottery Plugin
1 rule 1 TTP 1 CVEThe WooCommerce Lottery plugin for WordPress is vulnerable to unauthenticated time-based SQL injection via the 'orderby' and 'order' GET parameters, allowing attackers to extract sensitive database information.
Dolibarr Members REST API Improper Authorization Vulnerability
2 rules 2 TTPs 1 CVEAn improper authorization vulnerability (CVE-2026-71504) in Dolibarr prior to version 24.0.0 allows authenticated users to overwrite the credentials of any account via the Members REST API.
SQL Injection in Real Estate Management System
1 rule 2 TTPs 1 CVEThe itsourcecode Real Estate Management System 1.0 contains an SQL injection vulnerability in search.php that allows unauthenticated remote attackers to execute arbitrary database queries.
SQL Injection Vulnerability in Cisco Unified Intelligence Center
1 TTPA vulnerability in the Cisco Unified Intelligence Center allows a remote, authenticated attacker to perform a SQL injection attack due to insufficient input validation.
SQL Injection in Simple Online Food Ordering System
2 rules 1 TTP 1 CVESourceCodester Simple Online Food Ordering System 1.0 is vulnerable to unauthenticated SQL injection via the admin login endpoint, allowing remote attackers to execute arbitrary SQL commands.
Oracle Database SQL Injection Leads to OS-Level RCE and khunt Toolkit Deployment
3 TTPs 1 IOCA threat actor exploited SQL injection in a public-facing application to achieve OS-level remote code execution by abusing Oracle Java Source to deploy the custom 'khunt' post-exploitation toolkit.
SQL Injection Vulnerability in SuiteCRM
1 TTPAn authenticated remote attacker can exploit a SQL injection vulnerability in SuiteCRM to potentially gain unauthorized database access or manipulate backend data.
SQL Injection in The Gallery by BestWebSoft WordPress Plugin
1 TTP 1 CVEThe Gallery by BestWebSoft plugin for WordPress up to version 4.7.9 contains an SQL injection vulnerability via the '_gallery_order_{post_id}' parameter allowing authenticated attackers with Editor-level access to extract database information.
SQL Injection in SourceCodester Simple Client Management System
1 rule 1 TTP 1 CVEAn unauthenticated remote SQL injection vulnerability exists in the SourceCodester Simple Client Management System 1.0 that allows attackers to manipulate database queries via the ID parameter.
Path Traversal Vulnerability in Budibase
1 rule 4 TTPs 1 CVEBudibase versions before 3.40.0 are vulnerable to path traversal via maliciously crafted S3 object keys, allowing authenticated builders to perform arbitrary file writes during workspace export.
SQL Injection in Pimcore via ClassDefinition UID
1 rule 1 TTPAn improper input validation in Pimcore's ClassDefinition UID and unsanitized SQL query construction allow authenticated users to perform UNION-based SQL injection and exfiltrate database contents.
SQL Injection Vulnerability in MingSoft MCMS
1 rule 1 TTP 1 CVEMingSoft MCMS versions up to 3.0.6 contain a remote SQL injection vulnerability in the ms-mdiy component, allowing unauthenticated attackers to manipulate the formFields argument to execute arbitrary database queries.
SQL Injection in CodeIgniter4 Query Builder deleteBatch Method
1 TTP 1 CVEA SQL injection vulnerability in CodeIgniter4 (CVE-2026-63221) allows unauthenticated attackers to execute arbitrary SQL via improperly handled where() clauses when using the deleteBatch() method.
SQL Injection Vulnerability in Loca Software CMS
1 rule 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2026-5134) in Loca Software CMS allows remote attackers to execute arbitrary database commands.
SQL Injection in ESAFENET CDG
1 rule 2 TTPs 1 CVEA publicly exploitable SQL injection vulnerability in ESAFENET CDG allows unauthenticated remote attackers to execute arbitrary database queries via the keyid parameter.
SQL Injection in Sequelize Oracle Dialect
1 TTPSequelize v6.37.3 and earlier versions contain a critical SQL injection vulnerability in the Oracle dialect implementation, allowing unauthenticated attackers to bypass input sanitization and execute arbitrary SQL.
Blind SQL Injection in Krayin CRM leads DataGrid
1 rule 1 TTP 1 CVEKrayin CRM versions prior to 2.2.4 contain a blind SQL injection vulnerability in the leads DataGrid, allowing authenticated attackers to exfiltrate database contents via the rotten_lead[in] query parameter.
SQL Injection in SiYuan via /api/search/searchEmbedBlock
1 rule 2 TTPs 2 CVEs 1 IOCSiYuan versions 3.7.2 and earlier contain a critical SQL injection vulnerability in the /api/search/searchEmbedBlock endpoint, allowing unauthenticated or low-privileged users to execute stacked SQL queries and modify database content.
TrueBooker WordPress Plugin SQL Injection Vulnerability (CVE-2026-13161)
1 rule 2 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-13161, a generic SQL Injection vulnerability in the TrueBooker - Appointment Booking and Scheduler System plugin for WordPress affecting versions up to and including 1.2.2, by manipulating the 'alldata[truebooker_user]' parameter in POST requests, allowing the extraction of sensitive database information.
WordPress Booking Package Plugin Vulnerable to Unauthenticated SQL Injection
1 TTP 1 CVEThe Booking Package plugin for WordPress is vulnerable to unauthenticated generic SQL Injection via the 'email' form parameter in versions up to and including 1.7.20, allowing attackers to extract sensitive information from the database.
Multiple Vulnerabilities in SPIP CMS Lead to Data Confidentiality Loss
3 TTPsMultiple vulnerabilities, including SQL injection and indirect remote code injection (XSS), were discovered in SPIP Content Management System versions prior to 4.4.16, allowing an attacker to compromise data confidentiality and execute malicious code in user browsers.
Multiple SQL Injection Vulnerabilities in Tenable Nessus (CVE-2026-57587, CVE-2026-57588)
1 TTP 2 CVEs 10 IOCsMultiple SQL injection vulnerabilities, CVE-2026-57587 and CVE-2026-57588, have been discovered in Tenable Nessus versions prior to 10.12.0, allowing an attacker to perform unauthorized access to or manipulation of the underlying database through specially crafted input.
Joomla! Calendar Planner 1.0.1 SQL Injection (CVE-2017-20267)
1 rule 1 TTPAn unauthenticated attacker can exploit CVE-2017-20267, an SQL injection vulnerability in Joomla! Component Calendar Planner 1.0.1, by sending malicious GET requests to the 'events' view via the 'category_id' parameter, allowing for sensitive database information extraction.
Joomla SP Movie Database Unauthenticated SQL Injection (CVE-2017-20266)
2 rules 3 TTPs 1 CVEAn SQL injection vulnerability, CVE-2017-20266, in Joomla SP Movie Database version 1.3 allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the `searchword` parameter in GET requests to the `searchresults` view, enabling extraction of sensitive database information.
Joomla! FocalPoint Pro/Free SQL Injection (CVE-2017-20263)
1 rule 3 TTPs 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2017-20263) in Joomla! Component FocalPoint Pro/Free version 1.2.3 allows attackers to execute arbitrary SQL queries via a crafted 'id' parameter in GET requests, leading to sensitive database information disclosure.
Joomla! User Bench Component SQL Injection (CVE-2017-20254)
1 rule 3 TTPsAn unauthenticated attacker can exploit CVE-2017-20254, an SQL injection vulnerability in the Joomla! Component User Bench 1.0, by sending crafted HTTP GET requests to extract sensitive database information including credentials and configuration data.
CVE-2017-20252: Joomla NextGen Editor SQL Injection
2 rules 4 TTPsJoomla NextGen Editor 2.1.0 contains an SQL injection vulnerability (CVE-2017-20252) that allows unauthenticated attackers to execute arbitrary SQL commands through the `plname` parameter in crafted GET requests to `index.php?option=com_nge&view=config`, leading to the extraction of sensitive database information.
Multiple Vulnerabilities Discovered in SAP Products Including SQLi, XSS, and Policy Bypass
2 rules 5 TTPs 5 IOCsMultiple high-severity vulnerabilities discovered in various SAP products, including SQL injection (SQLi), remote indirect code injection (XSS), and security policy bypasses, could allow unauthenticated attackers to compromise sensitive enterprise systems by June 2026.
CVE-2018-25433 - Joomla JE Photo Gallery SQL Injection
1 rule 1 TTP 1 CVEJoomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability, tracked as CVE-2018-25433, allowing unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter.
GEO my WP WordPress Plugin SQL Injection Vulnerability (CVE-2026-9757)
2 rules 1 TTP 1 CVEThe GEO my WP plugin for WordPress is vulnerable to SQL Injection (CVE-2026-9757) via the 'swlatlng' and 'nelatlng' parameters, allowing unauthenticated attackers to extract sensitive information from the database by injecting SQL queries into a BETWEEN clause.
SQL Injection Vulnerability in ezsystems ezpublish-legacy dfscleanup
1 rule 1 TTPA SQL injection vulnerability exists in ezpublish-legacy, specifically in the dfscleanup.php script and the `_getFileList` function of the `eZDFSFileHandlerMySQLiBackend` class, allowing an attacker with local shell access to potentially expose sensitive data such as user credentials.
CVE-2026-7797: WordPress Simply Schedule Appointments Plugin Time-Based Blind SQL Injection
2 rules 1 TTP 1 CVEThe Appointment Booking Calendar WordPress plugin is vulnerable to time-based blind SQL Injection (CVE-2026-7797) via the 'append_where_sql' parameter, allowing unauthenticated attackers to extract sensitive information from the database by injecting SQL queries through the /appointments/bulk REST endpoint with a specific request format.
WP Contact Form 7 DB Handler Plugin CSRF leading to Arbitrary File Deletion (CVE-2026-6455)
2 rules 3 TTPs 1 CVEThe WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF), leading to arbitrary file deletion via SQL injection and PHP object injection due to missing nonce verification and unsafe deserialization, allowing attackers to delete arbitrary files on the server.
OpenCATS 0.9.7.4 SQL Injection Vulnerability
2 rules 1 TTPA SQL Injection vulnerability exists in OpenCATS 0.9.7.4, with a published exploit that allows for database version and user extraction on unpatched systems.
itsourcecode Courier Management System SQL Injection Vulnerability (CVE-2026-9606)
2 rules 1 TTP 1 CVEitsourcecode Courier Management System 1.0 is vulnerable to SQL injection (CVE-2026-9606) via the /manage_user.php file, allowing remote attackers to manipulate the ID argument and potentially execute arbitrary SQL commands.
itsourcecode Electronic Judging System 1.0 SQL Injection Vulnerability (CVE-2026-9528)
2 rules 1 TTP 1 CVEitsourcecode Electronic Judging System 1.0 is vulnerable to SQL injection via the judge_id parameter in /admin/delete_judge.php, allowing remote attackers to execute arbitrary SQL queries.
Joomla eXtroForms SQL Injection Vulnerability (CVE-2018-25380)
2 rules 1 TTP 1 CVEJoomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability (CVE-2018-25380) that allows authenticated attackers to execute arbitrary SQL commands via crafted POST requests, potentially leading to sensitive data exposure.
MooSocial Store Plugin 2.6 Blind SQL Injection Vulnerability (CVE-2018-25371)
2 rules 1 TTP 1 CVEMooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability, identified as CVE-2018-25371, allowing unauthenticated attackers to manipulate database queries via the 'product' parameter, potentially leading to sensitive data extraction.
WordPress Ultimate Form Builder Lite Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEWordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability (CVE-2018-25352) that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter, potentially leading to privilege escalation.
WordPress Contact Form Maker Plugin SQL Injection Vulnerability (CVE-2018-25347)
2 rules 1 TTP 1 CVEWordPress Contact Form Maker Plugin version 1.12.20 is vulnerable to SQL injection, enabling authenticated attackers to manipulate database queries via AJAX actions (FormMakerSQLMapping and generete_csv_fmc) by injecting malicious SQL code through the 'name' and 'search_labels' parameters, potentially extracting sensitive database information or escalating privileges.
WordPress Form Maker Plugin SQL Injection Vulnerability (CVE-2018-25346)
2 rules 1 TTP 1 CVEWordPress Form Maker Plugin version 1.12.24 and below is vulnerable to SQL injection, allowing authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv actions via crafted POST requests, potentially leading to data extraction, modification, or privilege escalation.
Multiple Vulnerabilities in Roundcube Webmail
2 rules 3 TTPsMultiple vulnerabilities in Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1 could lead to remote code execution, data confidentiality breaches, data integrity breaches, SSRF, and SQL Injection.
Multiple Vulnerabilities in Roundcube Webmail
2 rules 3 TTPsMultiple vulnerabilities in Roundcube Webmail allow an attacker to perform SQL injection attacks, bypass security measures, manipulate data, disclose confidential information, obtain extended privileges, execute arbitrary code, or perform cross-site scripting attacks.
YesWiki Unauthenticated SQL Injection Vulnerability
2 rules 1 TTPYesWiki versions prior to 4.6.4 are vulnerable to an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`), allowing an unauthenticated attacker to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes (CVE-2026-46670).
Actively Exploited Vulnerabilities in Sparx Pro Cloud Server and Enterprise Architect
2 rules 3 TTPs 5 CVEsMultiple vulnerabilities, including a critical authentication bypass (CVE-2026-42097), affect Sparx Systems Pro Cloud Server and Enterprise Architect, potentially leading to remote code execution and data compromise; active exploitation is likely given available PoCs.
CVE-2026-9010 - WordPress Boost Plugin Time-Based SQL Injection
1 rule 1 TTP 1 CVEThe Boost plugin for WordPress is vulnerable to time-based SQL Injection (CVE-2026-9010) via the 'current_url' and 'user_name' parameters in versions up to 2.0.3, allowing unauthenticated attackers to extract sensitive information from the database due to insufficient input sanitization.
Creative Mail WordPress Plugin Vulnerable to SQL Injection (CVE-2026-3985)
2 rules 1 TTP 1 CVEThe Creative Mail plugin for WordPress is vulnerable to SQL Injection due to insufficient escaping of the 'checkout_uuid' parameter and lack of sufficient preparation on the SQL query in the `has_checkout_consent()` method, allowing unauthenticated attackers to extract sensitive information from the database.
LiteLLM SQL Injection Vulnerability (CVE-2025-45809)
2 rules 1 TTP 1 IOCA SQL Injection vulnerability (CVE-2025-45809) in LiteLLM versions prior to 1.81.0 allows unauthenticated attackers to potentially steal database contents and read server files via time-based blind SQL injection in the `/key/block` and `/key/unblock` endpoints.
Redaxo CMS MyEvents Addon SQL Injection Vulnerability (CVE-2018-25319)
2 rules 1 TTP 1 CVERedaxo CMS Addon MyEvents version 2.2.1 contains an SQL injection vulnerability (CVE-2018-25319) that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter, enabling the extraction or modification of sensitive database information.
CVE-2020-37244: Supsystic Membership 1.4.7 Unauthenticated SQL Injection Vulnerability
2 rules 1 TTP 1 CVESupsystic Membership version 1.4.7 is vulnerable to SQL injection (CVE-2020-37244), allowing unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters, potentially extracting sensitive database information.
PHP Timeclock 1.04 Unauthenticated SQL Injection Vulnerability
2 rules 1 TTP 1 CVEPHP Timeclock 1.04 is vulnerable to time-based and boolean-based blind SQL injection in the login_userid parameter of login.php, allowing unauthenticated attackers to extract sensitive database information by sending crafted POST requests with SQL payloads.
Multiple Vulnerabilities in PostgreSQL Allow for Remote Code Execution and Data Breach
2 rules 6 TTPs 4 CVEsMultiple vulnerabilities in PostgreSQL versions 14.x, 15.x, 16.x, 17.x and 18.x could allow for arbitrary code execution, remote denial of service, and data breach, potentially leading to complete system compromise.
CVE-2025-11024: Akilli Commerce E-Commerce Website Blind SQL Injection Vulnerability
2 rules 1 TTP 1 CVECVE-2025-11024 is a critical SQL injection vulnerability affecting Akilli Commerce Software Technologies Ltd. Co.'s E-Commerce Website before version 4.5.001, allowing for blind SQL injection.
JoomSport WordPress Plugin Vulnerable to Time-Based Blind SQL Injection (CVE-2026-6929)
2 rules 1 TTP 1 CVEThe JoomSport plugin for WordPress is vulnerable to time-based blind SQL Injection (CVE-2026-6929) via the 'sortf' parameter in versions up to 5.7.7, allowing unauthenticated attackers to extract sensitive information from the database.
Multiple Vulnerabilities in n8n Allow for Remote Code Execution and Data Manipulation
2 rules 7 TTPsAn authenticated, remote attacker can exploit multiple vulnerabilities in n8n to execute arbitrary code, bypass security measures, conduct SQL injection attacks, manipulate data, or disclose sensitive information.
Multiple Vulnerabilities in Centreon Products
2 rules 1 TTP 1 IOCMultiple vulnerabilities in Centreon products allow for remote code execution, SQL injection, and cross-site scripting.
AIWU WordPress Plugin Vulnerable to SQL Injection (CVE-2026-2993)
2 rules 1 TTP 1 CVEThe AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection (CVE-2026-2993) in versions up to 1.4.17, allowing unauthenticated attackers to extract sensitive information from the database.
SourceCodester SUP Online Shopping 1.0 SQL Injection Vulnerability
2 rules 1 TTP 1 CVESourceCodester SUP Online Shopping 1.0 is vulnerable to SQL injection via the msgid parameter in /admin/replymsg.php, allowing remote attackers to execute arbitrary SQL commands.
BetterDocs Pro Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEThe BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions, allowing unauthenticated attackers to extract sensitive information from the database.
Ghost CMS 6.19.0 SQL Injection Vulnerability
2 rules 1 TTPA SQL injection vulnerability exists in Ghost CMS 6.19.0, and a public exploit (EDB-52555) is available, increasing the risk to unpatched systems.
Daptin SQL Injection Vulnerability via Fuzzy Search
2 rules 4 TTPsDaptin versions up to 0.11.4 are vulnerable to SQL injection, where an authenticated user can inject unvalidated column names into raw SQL via the `processFuzzySearch` function, allowing them to read the entire database.
Gravity Bookings Premium Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEThe Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in versions up to 2.5.9, allowing unauthenticated attackers to extract sensitive information from the database.
WeePie Cookie Allow Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEThe WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in versions up to 3.4.11, allowing unauthenticated attackers to extract sensitive information from the database.
Geo Mashup WordPress Plugin Vulnerable to Time-Based SQL Injection (CVE-2026-4062)
2 rules 1 TTP 1 CVEThe Geo Mashup WordPress plugin is vulnerable to Time-Based SQL Injection due to insufficient input sanitization, allowing unauthenticated attackers to extract sensitive database information.
Sunnet CTMS SQL Injection Vulnerability (CVE-2026-7489)
2 rules 1 TTP 1 CVESunnet CTMS is vulnerable to SQL injection (CVE-2026-7489), allowing authenticated remote attackers to execute arbitrary SQL commands and compromise the database.
SourceCodester Advanced School Management System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA SQL injection vulnerability (CVE-2026-7545) exists in SourceCodester Advanced School Management System 1.0 within the checkEmail endpoint of commonController.php, allowing remote attackers to potentially execute arbitrary SQL commands.
SSCMS v7.4.0 SQL Injection Vulnerability in stl:sqlContent Tag
2 rules 1 TTP 1 CVESSCMS v7.4.0 is vulnerable to SQL injection via the stl:sqlContent tag's queryString attribute, allowing attackers to execute arbitrary SQL statements through crafted payloads submitted to the /api/stl/actions/dynamic endpoint.
Multiple Vulnerabilities in MISP Threat Intelligence Platform
2 rules 1 TTPMultiple vulnerabilities in MISP versions prior to 2.5.37 allow attackers to perform privilege escalation, SQL injection (SQLi), and security policy bypass.
ProFTPD SQL Injection Vulnerability
2 rules 1 TTPAn anonymous remote attacker can exploit a SQL injection vulnerability in ProFTPD.
SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0 via manipulation of the ID parameter in the /ajax.php?action=delete_category endpoint, potentially leading to unauthorized data access or modification.
SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability
2 rules 1 TTP 1 CVESourceCodester Pharmacy Sales and Inventory System 1.0 is vulnerable to SQL injection by manipulating the ID argument in the /ajax.php?action=save_receiving file, allowing remote attackers to execute arbitrary SQL commands.
code-projects Employee Management System SQL Injection Vulnerability (CVE-2026-7063)
2 rules 1 TTP 1 CVECVE-2026-7063 is a SQL Injection vulnerability in code-projects Employee Management System 1.0 via the 'pwd' parameter in /370project/process/eprocess.php, enabling remote attackers to execute arbitrary SQL commands.
Multiple Vulnerabilities in n8n Workflow Automation Tool
3 rules 5 TTPs 1 CVEMultiple vulnerabilities in n8n can be exploited by an attacker to execute arbitrary code, bypass security measures, disclose sensitive information, conduct SQL injection attacks, cause denial-of-service, perform cross-site scripting, redirect users, or hijack sessions.
Dagster SQL Injection Vulnerability in Dynamic Partition Keys
2 rules 6 TTPsA SQL injection vulnerability exists in Dagster's DuckDB, Snowflake, BigQuery, and DeltaLake I/O managers, where a user with 'Add Dynamic Partitions' permission can inject arbitrary SQL due to improper escaping of dynamic partition key values, leading to unauthorized data access or modification.
ManageEngine PAM360 and Password Manager Pro Authenticated SQL Injection Vulnerability (CVE-2026-5785)
2 rules 4 TTPs 1 CVEAn authenticated SQL injection vulnerability (CVE-2026-5785) in the query report module of Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 allows attackers with low privileges to potentially read or modify sensitive database information.
Riaxe Product Customizer WordPress Plugin SQL Injection Vulnerability
2 rules 1 TTP 1 CVEThe Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter within 'product_data' of the `/wp-json/InkXEProductDesignerLite/add-item-to-cart` REST API endpoint, allowing unauthenticated attackers to extract sensitive information from the database.
manikandan580 School-management-system SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA time-based blind SQL injection vulnerability in manikandan580 School-management-system 1.0 allows unauthenticated attackers to potentially execute arbitrary SQL queries and gain unauthorized access to sensitive information.
Fortinet FortiDDoS-F SQL Injection Vulnerability (CVE-2026-39815)
2 rules 3 TTPs 1 CVEAn SQL injection vulnerability (CVE-2026-39815) in Fortinet FortiDDoS-F versions 7.2.1 through 7.2.2 may allow a low-privilege attacker to execute unauthorized code or commands.
PHPGurukul Daily Expense Tracking System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability exists in PHPGurukul Daily Expense Tracking System 1.1 within the /register.php file, where manipulation of the email argument allows for arbitrary SQL command execution, with a public exploit available.
SQL Injection Vulnerability in Simple Content Management System 1.0
2 rules 1 TTP 1 CVE 1 IOCA remote SQL injection vulnerability exists in code-projects Simple Content Management System 1.0, specifically affecting the /web/admin/login.php file where manipulation of the 'User' argument allows unauthenticated attackers to execute arbitrary SQL queries.
SQL Injection Vulnerability in Vehicle Showroom Management System 1.0
2 rules 1 TTP 1 CVEA remote attacker can exploit an SQL injection vulnerability (CVE-2026-6165) in code-projects Vehicle Showroom Management System 1.0 by manipulating the ID parameter in /util/Login_check.php, potentially leading to unauthorized data access and modification.
Dolibarr ERP-CRM 8.0.4 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEDolibarr ERP-CRM 8.0.4 is vulnerable to SQL injection via the rowid parameter in the admin dict.php endpoint, allowing attackers to execute arbitrary SQL queries and extract sensitive database information.
ImpressCMS 1.3.11 Time-Based Blind SQL Injection Vulnerability
2 rules 1 TTP 1 CVE 1 IOCImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability allowing authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter via POST requests to the admin.php endpoint.
CMSsite 1.0 SQL Injection Vulnerability (CVE-2019-25697)
2 rules 2 TTPs 1 CVECMSsite 1.0 is vulnerable to unauthenticated SQL injection (CVE-2019-25697) via the cat_id parameter in category.php, allowing attackers to extract sensitive database information.
SQL Injection Vulnerability in Vehicle Showroom Management System 1.0 (CVE-2026-6036)
2 rules 2 TTPs 1 CVEA remote SQL injection vulnerability (CVE-2026-6036) exists in the Vehicle Showroom Management System 1.0 due to improper sanitization of the VEHICLE_ID parameter in /util/VehicleDetailsFunction.php, potentially allowing attackers to execute arbitrary SQL commands.
Simple IT Discussion Forum SQL Injection Vulnerability (CVE-2026-5827)
2 rules 1 TTP 1 CVECVE-2026-5827 is a SQL injection vulnerability in code-projects Simple IT Discussion Forum 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'content' argument in /question-function.php.
WooCommerce Ajax Product Filter Plugin Vulnerable to SQL Injection (CVE-2026-3396)
2 rules 1 TTP 1 CVEThe WCAPF - WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection (CVE-2026-3396) due to insufficient escaping and SQL query preparation, allowing unauthenticated attackers to extract sensitive information from the database in versions up to 4.2.3.
code-projects Online FIR System SQL Injection Vulnerability
2 rules 1 TTP 1 CVE 1 IOCA SQL injection vulnerability in code-projects Online FIR System 1.0 allows remote attackers to execute arbitrary SQL commands by manipulating the email or password parameters in the /Login/checklogin.php file.
GLPI SQL Injection Vulnerability (CVE-2026-29047)
2 rules 1 TTP 1 CVEGLPI versions 10.0.0 before 10.0.24 and 11.0.6 are vulnerable to SQL Injection (CVE-2026-29047) via the logs export feature, allowing authenticated users to potentially execute arbitrary SQL commands.
SQL Injection Vulnerability in Car Rental Project 1.0 (CVE-2026-5634)
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-5634) exists in projectworlds Car Rental Project 1.0 via the fname parameter in /book_car.php, allowing unauthenticated attackers to potentially read, modify, or delete database information.
Kados R10 GreenBee SQL Injection Vulnerability (CVE-2019-25692)
2 rules 1 TTP 1 CVEKados R10 GreenBee is vulnerable to SQL injection via the 'id_to_modify' parameter, enabling attackers to manipulate database queries and potentially extract or modify sensitive data.
OpenDocMan 1.3.4 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEOpenDocMan version 1.3.4 is vulnerable to SQL injection, allowing unauthenticated attackers to manipulate database queries via the 'where' parameter in search.php to extract sensitive information.
Advance Gift Shop Pro Script 2.0.3 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEAdvance Gift Shop Pro Script 2.0.3 is vulnerable to SQL injection via the 's' search parameter, allowing unauthenticated attackers to execute arbitrary SQL queries and extract sensitive database information.
eDirectory SQL Injection Vulnerability (CVE-2019-25675)
2 rules 2 TTPs 1 CVEUnauthenticated attackers can exploit SQL injection vulnerabilities in eDirectory (CVE-2019-25675) to bypass administrator authentication and disclose sensitive files.
PilusCart 1.4.1 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEPilusCart 1.4.1 is vulnerable to SQL injection, allowing unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter to extract sensitive database information.
News Website Script 2.0.5 SQL Injection Vulnerability
2 rules 1 TTP 1 CVENews Website Script 2.0.5 contains an SQL injection vulnerability (CVE-2019-25668) allowing unauthenticated attackers to extract sensitive information by injecting SQL code through the news ID parameter in GET requests.
ResourceSpace 8.6 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEResourceSpace 8.6 is vulnerable to SQL injection, allowing unauthenticated attackers to execute arbitrary SQL queries via the 'ref' parameter in GET requests to the watched_searches.php endpoint, leading to sensitive data extraction.
OpenProject SQL Injection Vulnerability (CVE-2026-34717)
2 rules 1 TTP 1 CVEOpenProject versions before 17.2.3 are susceptible to SQL injection due to improper input sanitization in the '=n' operator, potentially allowing remote attackers to execute arbitrary SQL commands.
OpenSTAManager Time-Based Blind SQL Injection Vulnerability
2 rules 1 TTPOpenSTAManager versions before 2.10.2 are susceptible to time-based blind SQL injection via the 'options[stato]' GET parameter, allowing authenticated attackers to extract sensitive database information.
code-projects Accounting System 1.0 SQL Injection Vulnerability (CVE-2026-5034)
2 rules 1 TTPA remote SQL injection vulnerability exists in code-projects Accounting System 1.0 via manipulation of the 'cos_id' parameter in '/edit_costumer.php', potentially allowing unauthorized database access.
Group-Office JMAP Contact/Query SQL Injection Vulnerability
2 rules 3 TTPsAn authenticated SQL Injection vulnerability in Group-Office's JMAP Contact/query endpoint allows data extraction, including session tokens, leading to account takeover if unpatched.
Critical Vulnerabilities in n8n Workflow Automation Tool
3 rules 2 TTPsMultiple critical vulnerabilities in n8n, including prototype pollution, code injection, and SQL injection, allow authenticated users to achieve remote code execution, read sensitive files, and perform unauthorized database operations.
KomSeo Cart 1.3 SQL Injection Vulnerability
2 rules 1 TTPKomSeo Cart 1.3 is vulnerable to SQL injection via the 'my_item_search' parameter in edit.php, allowing attackers to inject SQL commands and extract sensitive database information.
Wecodex Hotel CMS 1.0 SQL Injection Vulnerability
2 rules 1 TTPWecodex Hotel CMS 1.0 is vulnerable to SQL injection in the admin login functionality, allowing unauthenticated attackers to bypass authentication and potentially extract sensitive database information or gain administrative access by injecting SQL code through the username parameter in POST requests to index.php with action=processlogin.
SQL Injection Vulnerability in Simple Laundry System 1.0
2 rules 1 TTPA remote SQL Injection vulnerability exists in code-projects Simple Laundry System 1.0 within the Parameter Handler component's /checkregisitem.php file, where manipulating the Long-arm-shirtVol argument can trigger the injection, with a publicly available exploit.
SQL Injection Vulnerability in itsourcecode Online Enrollment System 1.0
2 rules 1 TTPA remote SQL injection vulnerability exists in itsourcecode Online Enrollment System 1.0 within the Parameter Handler component affecting the `/sms/grades/index.php` file, allowing unauthorized database access and has been publicly disclosed.
SourceCodester Malawi Online Market SQL Injection Vulnerability (CVE-2026-4838)
2 rules 1 TTPA remote SQL injection vulnerability (CVE-2026-4838) exists in the /display.php file of SourceCodester Malawi Online Market 1.0 due to improper input sanitization of the ID parameter, potentially allowing attackers to execute arbitrary SQL queries.
OpenEMR Blind SQL Injection Vulnerability in Patient Search (CVE-2026-29187)
2 rules 1 TTPOpenEMR versions prior to 8.0.0.3 are susceptible to a blind SQL injection vulnerability in the Patient Search functionality, allowing authenticated attackers to execute arbitrary SQL commands by manipulating HTTP parameter keys.
Netartmedia Vlog System SQL Injection Vulnerability
2 rules 1 TTP 1 IOCNetartmedia Vlog System is vulnerable to SQL injection, allowing unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter in the forgotten_password module.
WWBN AVideo SQL Injection Vulnerability (CVE-2026-33723)
2 rules 1 TTPWWBN AVideo platform versions up to 26.0 are vulnerable to SQL injection (CVE-2026-33723), allowing authenticated attackers to inject arbitrary SQL commands via the 'user_id' POST parameter and extract sensitive data such as password hashes, API keys, and encryption salts.
WP Maps WordPress Plugin Time-Based SQL Injection Vulnerability (CVE-2026-2580)
2 rules 1 TTPThe WP Maps WordPress plugin before version 4.9.2 is vulnerable to time-based SQL Injection via the 'orderby' parameter, allowing unauthenticated attackers to extract sensitive information from the database.
LiteLLM Proxy API Key Verification SQL Injection
2 rules 1 TTPA SQL injection vulnerability exists in LiteLLM versions 1.81.16 to prior to 1.83.7 allowing an unauthenticated attacker to inject SQL queries via a crafted 'Authorization' header, potentially leading to unauthorized data access or modification.
WWBN AVideo Unauthenticated SQL Injection Vulnerability (CVE-2026-33485)
2 rules 1 TTPWWBN AVideo versions up to 26.0 are vulnerable to unauthenticated SQL injection via the RTMP `on_publish` callback, allowing attackers to extract sensitive database information.
MikroORM SQL Injection Vulnerability
2 rules 1 TTPMikroORM versions 6.6.9 and 7.0.5 are vulnerable to SQL injection when specially crafted objects are interpreted as raw SQL query fragments, potentially allowing attackers to execute arbitrary SQL commands.
JetEngine WordPress Plugin SQL Injection Vulnerability (CVE-2026-4352)
2 rules 1 TTP 1 CVEThe JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint, allowing unauthenticated attackers to extract sensitive database information.
AVideo Platform Unauthenticated SQL Injection Vulnerability
2 rules 1 TTPAVideo platform versions before 26.0 are vulnerable to unauthenticated SQL injection via the getAllCategories() method in objects/category.php due to insufficient sanitization of the doNotShowCats parameter, potentially leading to arbitrary code execution.
SourceCodester Hotel Management System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA SQL injection vulnerability exists in SourceCodester Hotel Management System 1.0 in the /index.php/reservation/check component due to improper sanitization of the room_type parameter, allowing a remote attacker to execute arbitrary SQL commands.
Wecodex Restaurant CMS 1.0 SQL Injection Vulnerability
2 rules 1 TTPWecodex Restaurant CMS 1.0 is vulnerable to SQL injection via the username parameter, allowing unauthenticated attackers to extract sensitive database information by sending crafted POST requests to the login endpoint.
WebOfisi E-Ticaret 4.0 SQL Injection Vulnerability (CVE-2018-25210)
2 rules 1 TTP 4 IOCsWebOfisi E-Ticaret 4.0 is vulnerable to SQL injection via the 'urun' GET parameter, allowing unauthenticated attackers to manipulate database queries and execute various SQL injection attacks.
Vendure Shop API Unauthenticated SQL Injection Vulnerability (CVE-2026-40887)
2 rules 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2026-40887) exists in the Vendure Shop API affecting PostgreSQL, MySQL/MariaDB, and SQLite databases, where a user-controlled query string parameter is directly interpolated into a raw SQL expression, potentially leading to arbitrary code execution.
qdPM 9.1 SQL Injection Vulnerability (CVE-2018-25208)
2 rules 1 TTPqdPM version 9.1 is vulnerable to SQL injection, allowing unauthenticated attackers to extract sensitive database information by injecting malicious SQL code into the filter_by parameters of the timeReport endpoint.
NocoBase SQL Injection via Recursive Eager Loading
2 rules 4 TTPsNocoBase versions 2.0.32 and earlier are vulnerable to SQL injection due to string concatenation in the `queryParentSQL()` function, allowing attackers with record creation permissions to inject arbitrary SQL and potentially extract sensitive information or execute commands.
Craft Commerce Blind SQL Injection via hasVariant/hasProduct Properties
3 rules 1 TTP 1 CVEA blind SQL injection vulnerability exists in Craft Commerce's `ProductQuery::hasVariant` and `VariantQuery::hasProduct` properties, allowing authenticated control panel users to extract arbitrary database contents and potentially escalate privileges.
SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability
2 rules 1 TTP 1 CVECVE-2026-6187 is a remote SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 via the ID parameter in /ajax.php?action=chk_prod_availability, allowing unauthenticated attackers to execute arbitrary SQL queries.
GeekyBot WordPress Plugin Vulnerable to SQL Injection
2 rules 1 TTP 1 CVEThe GeekyBot WordPress plugin is vulnerable to SQL Injection, allowing unauthenticated attackers to extract sensitive information from the database by manipulating the 'attributekey' parameter.