<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – SQL Injection (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/sql.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/sql-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – SQL Injection (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:30 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-15655 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15655</guid>
    <pubDate>Wed, 03 Jun 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15655</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection.  This issue affects School Management: from n/a through 93.2.0.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10704 – A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10704</guid>
    <pubDate>Wed, 03 Jun 2026 02:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10704</strong></p>
  <p>A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10620 – A flaw has been found in code-projects Student Admission System 1.0. Affected is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10620</guid>
    <pubDate>Tue, 02 Jun 2026 21:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10620</strong></p>
  <p>A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.php. This manipulation of the argument eid/did causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5076 – The ARMember Premium plugin for WordPress is vulnerable to an insecure password ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5076</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5076</strong></p>
  <p>The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a password reset. This is in addition to the hashed key that WordPress core stores securely in `wp_users.user_activation_key`. T…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5073 – The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5073</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5073</strong></p>
  <p>The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient escaping on the user-supplied 'order' and 'orderby' parameters and the lack of sufficient preparation on the existing SQL query in the `arm_get_directory_members()` function. Thi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10608 – A security flaw has been discovered in DedeCMS 5.7.88. This affects the function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10608</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10608</strong></p>
  <p>A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10607 – A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10607</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10607</strong></p>
  <p>A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10606 – A vulnerability was determined in DedeCMS 5.7.88. The affected element is the fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10606</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10606</strong></p>
  <p>A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a manipulation of the argument msg can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42684 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42684</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42684</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection.  This issue affects WP Job Portal: from n/a through 2.5.1.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24782 – Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24782</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24782</strong></p>
  <p>Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attacker with the FormBuilder role to retrieve information on or modify other users' form definitions and some global configuration parameters. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49491 – Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49491</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49491</strong></p>
  <p>Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10290 – A weakness has been identified in code-projects Hotel and Tourism Reservation Sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10290</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10290</strong></p>
  <p>A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25434 – WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25434</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25434</strong></p>
  <p>WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wpas_keys parameter. Attackers can send GET requests to autosuggest.php with crafted wpas_keys values to extract sensitive database information from WordPress posts and other tables.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25433 – Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25433</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25433</strong></p>
  <p>Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery component to execute arbitrary SQL queries and retrieve sensitive data like usernam…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25431 – No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25431</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25431</strong></p>
  <p>No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attackers to manipulate database queries. Attackers can submit POST requests to /nocms/main/manage_privilege/index/export with malicious SQL code in the order_by[0] parameter to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25430 – Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25430</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25430</strong></p>
  <p>Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the eGeqIdEquipe parameter. Attackers can send GET requests to the egeq.php endpoint with crafted SQL payloads to extract sensitive database information including version details and other data.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25429 – Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25429</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25429</strong></p>
  <p>Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the zProIdPro parameter. Attackers can send GET requests to zpro.php with crafted SQL payloads in the zProIdPro parameter to extract sensitive database information including usernames, databases, and version details.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25428 – Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25428</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25428</strong></p>
  <p>Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tRecIdListe parameter. Attackers can send GET requests to the trec.php endpoint with crafted SQL payloads to extract database information including table and column names.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45722 – Nextcloud is an open source content collaboration platform. From versions 0.9.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45722</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45722</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a query. Compared to normal SQL injections, the ORDER BY is limited to extracting a single bit of information per request or…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42672 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42672</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42672</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42672</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection.  This issue affects WP Directory Kit: from n/a through 1.5.1.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42672">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10263 – A vulnerability was found in SourceCodester Computer Repair Shop Management Syst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10263</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10263</strong></p>
  <p>A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10262 – A vulnerability has been found in code-projects Real State Services 1.0. This im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10262</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10262</strong></p>
  <p>A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10261 – A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10261</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10261</strong></p>
  <p>A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10260 – A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted el...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10260</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10260</strong></p>
  <p>A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10253 – A vulnerability was detected in itsourcecode Online House Rental System 1.0. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10253</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10253</strong></p>
  <p>A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10252 – A security vulnerability has been detected in itsourcecode Online House Rental S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10252</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10252</strong></p>
  <p>A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10251 – A weakness has been identified in itsourcecode Online House Rental System 1.0. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10251</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10251</strong></p>
  <p>A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10250 – A security flaw has been discovered in itsourcecode Online Blood Bank Management...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10250</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10250</strong></p>
  <p>A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10249 – A vulnerability was identified in itsourcecode Online Blood Bank Management Syst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10249</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10249</strong></p>
  <p>A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40546 – SOPlanning is vulnerable to SQL Injection across multiple endpoints and paramete...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40546</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40546</strong></p>
  <p>SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inject arbitrary SQL commands, potentially gaining full control over the database.  This issue affects SOPlanning version 1.55 and below.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10227 – A vulnerability has been found in raisulislamg4 student_management_system_by_php...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10227</guid>
    <pubDate>Mon, 01 Jun 2026 06:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10227</strong></p>
  <p>A vulnerability has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The affected element is an unknown function of the file add_user_check.php of the component User Creation Handler. The manipulation of the argument role leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public a…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10226 – A flaw has been found in raisulislamg4 student_management_system_by_php up to 31...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10226</guid>
    <pubDate>Mon, 01 Jun 2026 06:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10226</strong></p>
  <p>A flaw has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. Impacted is an unknown function of the file delete.php. Executing a manipulation of the argument user_id/course_id/teacher_id/student_id/application_id can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. This product op…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10225 – A vulnerability was detected in raisulislamg4 student_management_system_by_php u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10225</guid>
    <pubDate>Mon, 01 Jun 2026 06:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10225</strong></p>
  <p>A vulnerability was detected in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. This issue affects some unknown processing of the file login_check.php of the component Login. Performing a manipulation of the argument Username results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48188 – An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48188</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48188</strong></p>
  <p>An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the NO_BACKSLASH_ESCAPES SQL mode.  This issue affects OTRS:     *  7.0.X   *  8.0.X   *  2023.X   *  2024.X   *  2025.X   *  2026…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10208 – A flaw has been found in code-projects Online Hospital Management System 1.php. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10208</guid>
    <pubDate>Mon, 01 Jun 2026 02:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10208</strong></p>
  <p>A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10186 – A security vulnerability has been detected in code-projects Online Hospital Mana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10186</guid>
    <pubDate>Sun, 31 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10186</strong></p>
  <p>A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10185 – A weakness has been identified in SourceCodester Hospitals Patient Records Manag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10185</guid>
    <pubDate>Sun, 31 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10185</strong></p>
  <p>A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10184 – A security flaw has been discovered in SourceCodester Hospitals Patient Records ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10184</guid>
    <pubDate>Sun, 31 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10184</strong></p>
  <p>A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49490 – OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49490</guid>
    <pubDate>Sun, 31 May 2026 13:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49490</strong></p>
  <p>OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the Candidates DataGrid. Attackers can bypass column filterable restrictions by manipulating filter requests to execute arbitrary SQL queries against the database.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49489 – OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49489</guid>
    <pubDate>Sun, 31 May 2026 13:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49489</strong></p>
  <p>OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL via the sortDirection parameter in ajax/getDataGridPager.php to perform time-based blind injection attacks and read sensitive data.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10178 – A vulnerability was detected in code-projects Online Music Site 1.0. This vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10178</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10178</guid>
    <pubDate>Sun, 31 May 2026 11:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10178</strong></p>
  <p>A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminEditAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10178">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25425 – Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25425</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25425</strong></p>
  <p>Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid and cid parameters. Attackers can send GET requests to index.php with crafted SQL payloads in the aid or cid parameters to extract database information including table and column names.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25424 – Gate Pass Management System 2.1 contains an SQL injection vulnerability that all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25424</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25424</strong></p>
  <p>Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST requests to login-exec.php with SQL injection payloads in form parameters to authenticate without valid credentials and gain access to the application.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25422 – MOGG web simulator Script contains an SQL injection vulnerability that allows un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25422</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25422</strong></p>
  <p>MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the id parameter. Attackers can send GET requests to play.php with crafted SQL payloads in the id parameter to extract sensitive database information including usernames and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25420 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25420</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25420</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to watch.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25419 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25419</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25419</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the genre parameter. Attackers can send GET requests to genre.php with crafted SQL payloads in the genre parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25418 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25418</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25418</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the year parameter. Attackers can send GET requests to year.php with crafted SQL payloads in the year parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25417 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25417</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25417</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. Attackers can send GET requests to quality.php with crafted SQL payloads in the quality parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25416 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25416</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25416</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the country parameter. Attackers can send GET requests to country.php with crafted SQL payloads in the country parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25415 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25415</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25415</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. Attackers can send GET requests to director.php with crafted SQL payloads in the director parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25414 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25414</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25414</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the actor parameter. Attackers can send GET requests to actor.php with crafted SQL payloads in the actor parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25413 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25413</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25413</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. Attackers can send GET requests to search.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25411 – MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25411</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25411</strong></p>
  <p>MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to email.php with crafted SQL payloads in the 'id' parameter to extract sensitive database information including table and column names.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25410 – SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25410</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25410</strong></p>
  <p>SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to /admin/media.php with module=pengurus and act=editpengurus parameters containing SQL UNION statements to extract database information including usernames, database names, and version de…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25407 – eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25407</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25407</strong></p>
  <p>eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters across publisher, diskusi, galeri, content, and about modules to extract database information including usernames, d…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25406 – eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25406</guid>
    <pubDate>Sat, 30 May 2026 16:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25406</strong></p>
  <p>eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters across publisher, diskusi, galeri, content, and about modules to extract database credentials, usernames, and versio…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25405 – eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25405</guid>
    <pubDate>Sat, 30 May 2026 16:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25405</strong></p>
  <p>eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9757 – The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9757</guid>
    <pubDate>Sat, 30 May 2026 10:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9757</strong></p>
  <p>The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters are read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing WordPress's wp_magic_quotes protection, which only covers $_POST/$_GET/$_COOKIE/$_REQUEST), then each is split on ',' via explode() and the resulting fragments are…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10111 – A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10111</guid>
    <pubDate>Sat, 30 May 2026 08:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10111</strong></p>
  <p>A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function of the component Login Page. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10110 – A vulnerability was detected in code-projects Student Details Management System ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10110</guid>
    <pubDate>Sat, 30 May 2026 07:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10110</strong></p>
  <p>A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10105 – agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector datab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10105</guid>
    <pubDate>Fri, 29 May 2026 18:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10105</strong></p>
  <p>agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploit the unsafe f-string interpolation in clickhousedb.py to delete all rows, target specific rows, or extract information through error-based or bl…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25404 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25404</guid>
    <pubDate>Fri, 29 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25404</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ticket_id parameter. Attackers can send GET requests to add_facnote.php with crafted SQL payloads to extract sensitive database information including version details and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25403 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25403</guid>
    <pubDate>Fri, 29 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25403</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to city_graph.php with crafted SQL payloads to extract sensitive database information including schema names and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25402 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25402</guid>
    <pubDate>Fri, 29 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25402</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to inc_types_graph.php with crafted SQL payloads to extract sensitive database information including schema names and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25401 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25401</guid>
    <pubDate>Fri, 29 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25401</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to sever_graph.php with crafted SQL payloads to extract sensitive database information including schema names and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25400 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25400</guid>
    <pubDate>Fri, 29 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25400</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to the ajax/form_post.php endpoint with crafted SQL payloads to extract sensitive database information including schema names and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25399 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25399</guid>
    <pubDate>Fri, 29 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25399</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tick_lat and tick_lng parameters. Attackers can send GET requests to nearby.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25398 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25398</guid>
    <pubDate>Fri, 29 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25398</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the frm_passwd parameter. Attackers can send POST requests to main.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25395 – Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25395</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25395</strong></p>
  <p>Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the feature_id parameter of boards_buttons/update_feature.php. The feature_id value is concatenated directly into SQL statements without sanitization, allowing attackers to send a crafted GET request with a UNION-based payload to ext…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25394 – Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25394</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25394</strong></p>
  <p>Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the release_id parameter of boards_buttons/update_release.php. The release_id value is concatenated directly into SQL statements without sanitization, allowing attackers to send a crafted GET request with a UNION-based payload to ext…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25392 – MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25392</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25392</strong></p>
  <p>MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor, user, and jenis parameters in the log_activity function. Attackers can send POST requests to /index.php/user/log_activity with malicious SQL code in these parameters to extract sensitive database information including version and database names.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25390 – HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25390</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25390</strong></p>
  <p>HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-perdesa-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25389 – HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25389</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25389</strong></p>
  <p>HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter sent to lap-anggota-kelompok-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25386 – HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25386</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25386</strong></p>
  <p>HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while authenticated users can exploit the pengurus, fasilitas, and kelompok modules (for example act=print, act=editpengurus, act=editfa…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25385 – E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25385</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25385</strong></p>
  <p>E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id_partai parameter. Attackers can send GET requests to monitor_nilai.php with crafted SQL payloads in the id_partai parameter to extract sensitive database information including admin credentials and user data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25382 – Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25382</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25382</strong></p>
  <p>Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can send crafted requests to profile.php with UNION-based SQL injection payloads to retrieve table names, column names, and sensitive data from the information_schema database.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44238 – FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44238</guid>
    <pubDate>Fri, 29 May 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44238</strong></p>
  <p>FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parameters. Authentication with a FreePBX Administration Control Panel account that has CDR section access is required. Full administrator privileges are not needed. This vulnerability is fixed in 16.0.50 and 17.0.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4776 – An SQL injection vulnerability exists in Mautic's API contact filtering mechanis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4776</guid>
    <pubDate>Fri, 29 May 2026 08:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4776</strong></p>
  <p>An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45288 – Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45288</guid>
    <pubDate>Thu, 28 May 2026 21:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45288</strong></p>
  <p>Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without parameterization or validation, making every code path that exposes regConfig to untrusted input a SQL injection sink. This vulnerability is fixed in 8.36.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7797 – The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7797</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7797</strong></p>
  <p>The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6455 – The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6455</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6455</strong></p>
  <p>The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the nonce check is only executed when _wpnonce is present in the POST body, allowing it to be trivially…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44886 – Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 202...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44886</guid>
    <pubDate>Wed, 27 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44886</strong></p>
  <p>Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnerable to SQL injection. The /pialert/php/server/devices.php route accepts requests from unauthenticated users when the action URL parameter is set to getDevicesTotals. The scansource URL parameter is then injected in a SQL query. This vulnerability is…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44521 – elFinder is an open-source file manager for web, written in JavaScript using jQu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44521</guid>
    <pubDate>Wed, 27 May 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44521</strong></p>
  <p>elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to inject SQL through a crafted target file hash. Successful exploitation can lead to unauthorized dat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49046 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49046</guid>
    <pubDate>Wed, 27 May 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49046</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Blind SQL Injection.  This issue affects Duplicate Page and Post: from n/a through 2.9.5.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42761 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42761</guid>
    <pubDate>Wed, 27 May 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42761</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.9.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42755 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42755</guid>
    <pubDate>Wed, 27 May 2026 11:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42755</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allows Blind SQL Injection.This issue affects TableOn: from n/a through <= 1.0.5.1.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42747 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42747</guid>
    <pubDate>Wed, 27 May 2026 11:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42747</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder: from n/a through <= 4.0.6.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42740 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42740</guid>
    <pubDate>Wed, 27 May 2026 11:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42740</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Injection.This issue affects Tainacan: from n/a through <= 1.0.3.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42730 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42730</guid>
    <pubDate>Wed, 27 May 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42730</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy LMS: from n/a through <= 3.7.29.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42727 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42727</guid>
    <pubDate>Wed, 27 May 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42727</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.8.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8054 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8054</guid>
    <pubDate>Wed, 27 May 2026 09:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8054</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11.04-1 through 26.04.28-02 allows remote unauthenticated attackers to read, modify, or destroy arbitrary database content. The endpoints did not enforce authentication and accepted unsanitized input us…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40850 – An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40850</guid>
    <pubDate>Wed, 27 May 2026 09:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40850</strong></p>
  <p>An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40836 – An low privileged remote attacker can exploit an unauthenticated SQL Injection v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40836</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40836</guid>
    <pubDate>Wed, 27 May 2026 09:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40836</strong></p>
  <p>An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the inmessage model due to improper neutralization of special elements in a SQL DELETE command allowing for reading the whole database and deleting entries in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40836">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40834 – An low privileged remote attacker can exploit an unauthenticated SQL Injection v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40834</guid>
    <pubDate>Wed, 27 May 2026 09:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40834</strong></p>
  <p>An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.php files saveDashboardLayout function due to improper neutralization of special elements in a SQL INSERT command allowing for reading the whole database and inserting entries into a non critical table. This can result in a total loss of confidentiality and some loss of integrity.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40833 – An low privileged remote attacker can exploit an unauthenticated SQL Injection v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40833</guid>
    <pubDate>Wed, 27 May 2026 09:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40833</strong></p>
  <p>An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash.php files saveDashboardLayout function due to improper neutralization of special elements in a SQL INSERT command allowing for reading the whole database and inserting entries into a non critical table. This can result in a total loss of confidentiality and some loss of integrity.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40819 – An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40819</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40819</guid>
    <pubDate>Wed, 27 May 2026 08:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40819</strong></p>
  <p>An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40819">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40818 – An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40818</guid>
    <pubDate>Wed, 27 May 2026 08:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40818</strong></p>
  <p>An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevice function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40817 – An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40817</guid>
    <pubDate>Wed, 27 May 2026 08:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40817</strong></p>
  <p>An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40816 – An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40816</guid>
    <pubDate>Wed, 27 May 2026 08:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40816</strong></p>
  <p>An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files _mb24confi_getTagAlarm function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40815 – An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40815</guid>
    <pubDate>Wed, 27 May 2026 08:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40815</strong></p>
  <p>An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAccount function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40815">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
