<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Time-based SQL Injection (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/time-sql.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/time-sql-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Time-based SQL Injection (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-9010 – The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9010</guid>
    <pubDate>Wed, 20 May 2026 04:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9010</strong></p>
  <p>The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL queries. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing quer…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4798 – The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4798</guid>
    <pubDate>Wed, 13 May 2026 13:01:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4798</strong></p>
  <p>The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4062 – The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4062</guid>
    <pubDate>Sat, 02 May 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4062</strong></p>
  <p>The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. The `esc_sql()` function is applied but is ineffective because the values are placed i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4061 – The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4061</guid>
    <pubDate>Sat, 02 May 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4061</strong></p>
  <p>The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including, 1.13.18. This is due to the `SearchResults` hook explicitly calling `stripslashes_deep($_POST)` which removes WordPress magic quotes protection, followed by the unsanitized `map_post_type` value being concatenated into an `IN(...)` clause without `e…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4060 – The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4060</guid>
    <pubDate>Sat, 02 May 2026 12:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4060</strong></p>
  <p>The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The `esc_sql()` function is applied but is ineffective in the `ORDER BY` context because the value is not enclosed in q…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3396 – WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3396</guid>
    <pubDate>Wed, 08 Apr 2026 12:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3396</strong></p>
  <p>WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing quer…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39341 – ChurchCRM is an open-source church management system. Prior to 7.1.0, the applic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39341</guid>
    <pubDate>Tue, 07 Apr 2026 18:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39341</strong></p>
  <p>ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper input validation. Endpoint Reports/ConfirmReportEmail.php?familyId= is not correctly sanitising user input, specifically, the sanitised input is not used to create the SQL query. This vulnerability is fixed in 7.1.0.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-36058 – The Send Basket functionality in Koha Library before 23.05.10 is susceptible to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36058</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-36058</strong></p>
  <p>The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25664 – SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25664</guid>
    <pubDate>Sun, 05 Apr 2026 21:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25664</strong></p>
  <p>SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the index.php endpoint to extract sensitive database information through time-based blind SQL injection techniques.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2580 – The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp;...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2580</guid>
    <pubDate>Mon, 23 Mar 2026 00:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2580</strong></p>
  <p>The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1800 – The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-base...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1800</guid>
    <pubDate>Sat, 21 Mar 2026 04:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1800</strong></p>
  <p>The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedFnt’ parameter in all versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already e…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25535 – Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25535</guid>
    <pubDate>Thu, 12 Mar 2026 16:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25535</strong></p>
  <p>Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with time-based SQL injection payloads in the Email field to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25519 – Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25519</guid>
    <pubDate>Thu, 12 Mar 2026 16:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25519</strong></p>
  <p>Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the option parameter. Attackers can send POST requests to uyelik.php with crafted payloads in the option parameter to execute time-based SQL injection attacks and extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25500 – Simple Job Script contains an SQL injection vulnerability that allows unauthenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25500</guid>
    <pubDate>Wed, 04 Mar 2026 18:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25500</strong></p>
  <p>Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the employerid parameter. Attackers can send POST requests to the register-recruiters endpoint with time-based SQL injection payloads to extract sensitive data or modify database contents.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-50192 – Chamilo is a learning management system. Prior to version 1.11.30, there is a ti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50192</guid>
    <pubDate>Mon, 02 Mar 2026 15:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-50192</strong></p>
  <p>Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25490 – Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25490</guid>
    <pubDate>Fri, 27 Feb 2026 18:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25490</strong></p>
  <p>Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' parameter. Attackers can send GET requests to the admin/edit.php endpoint with time-based SQL injection payloads to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25460 – Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25460</guid>
    <pubDate>Sun, 22 Feb 2026 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25460</strong></p>
  <p>Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' GET parameter. Attackers can send requests to the arama endpoint with malicious 'q' values using time-based SQL injection techniques to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-25456 – Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25456</guid>
    <pubDate>Sun, 22 Feb 2026 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-25456</strong></p>
  <p>Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET parameter. Attackers can send requests to with time-based SQL injection payloads to extract sensitive database information or cause denial of service.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25439 – NoviSmart CMS contains an SQL injection vulnerability that allows remote attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25439</guid>
    <pubDate>Sun, 22 Feb 2026 14:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25439</strong></p>
  <p>NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2232 – The Product Table and List Builder for WooCommerce Lite plugin for WordPress is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2232</guid>
    <pubDate>Thu, 19 Feb 2026 17:24:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2232</strong></p>
  <p>The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 4.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1581 – The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1581</guid>
    <pubDate>Thu, 19 Feb 2026 17:24:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1581</strong></p>
  <p>The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can b…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2576 – The Business Directory Plugin – Easy Listing Directories for WordPress plugin fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2576</guid>
    <pubDate>Wed, 18 Feb 2026 05:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2576</strong></p>
  <p>The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'payment' parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addition…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37005 – TimeClock Software 1.01 contains an authenticated time-based SQL injection vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37005</guid>
    <pubDate>Thu, 29 Jan 2026 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37005</strong></p>
  <p>TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0702 – The VidShop – Shoppable Videos for WooCommerce plugin for WordPress is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0702</guid>
    <pubDate>Wed, 28 Jan 2026 09:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0702</strong></p>
  <p>The VidShop – Shoppable Videos for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'fields' parameter in all versions up to, and including, 1.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alrea…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14068 – The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14068</guid>
    <pubDate>Fri, 12 Dec 2025 07:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14068</strong></p>
  <p>The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions up to, and including, 0.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14068">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7402 – The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for Word...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7402</guid>
    <pubDate>Mon, 24 Nov 2025 05:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7402</strong></p>
  <p>The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘site_id’ parameter in all versions up to, and including, 4.95 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65024 – i-Educar is free, fully online school management software. In versions 2.10.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65024</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65024</strong></p>
  <p>i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda_admin_cad.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands against the application's database. This vulnerability is caused by the improper handling of the cod_agenda…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65023 – i-Educar is free, fully online school management software. In versions 2.10.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65023</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65023</strong></p>
  <p>i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/funcionario_vinculo_cad.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands against the application's database. This vulnerability is caused by the improper handling of the cod…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65022 – i-Educar is free, fully online school management software. In versions 2.10.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65022</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65022</strong></p>
  <p>i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands against the application's database. This vulnerability is caused by the improper handling of the cod_agenda request p…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4203 – The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4203</guid>
    <pubDate>Sat, 25 Oct 2025 07:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4203</strong></p>
  <p>The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x’s…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9807 – The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9807</guid>
    <pubDate>Fri, 12 Sep 2025 02:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9807</strong></p>
  <p>The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9172 – The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9172</guid>
    <pubDate>Tue, 26 Aug 2025 04:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9172</strong></p>
  <p>The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the ‘resource’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be us…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7670 – The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7670</guid>
    <pubDate>Tue, 19 Aug 2025 08:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7670</strong></p>
  <p>The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in all versions up to, and including, 6.1.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing querie…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6184 – The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6184</guid>
    <pubDate>Wed, 13 Aug 2025 07:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6184</strong></p>
  <p>The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter used in the get_submitted_assignments() function in all versions up to, and including, 3.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authentica…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7036 – The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7036</guid>
    <pubDate>Wed, 06 Aug 2025 02:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7036</strong></p>
  <p>The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13507 – The GeoDirectory – WP Business Directory Plugin and Classified Listings Director...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13507</guid>
    <pubDate>Sat, 26 Jul 2025 04:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13507</strong></p>
  <p>The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2.8.97 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6970 – The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6970</guid>
    <pubDate>Wed, 09 Jul 2025 23:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6970</strong></p>
  <p>The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL que…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5339 – The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for Word...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5339</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5339</guid>
    <pubDate>Wed, 02 Jul 2025 04:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5339</strong></p>
  <p>The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘bsa_pro_id’ parameter in all versions up to, and including, 4.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5339">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5590 – The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5590</guid>
    <pubDate>Thu, 26 Jun 2025 02:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5590</strong></p>
  <p>The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL qu…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5487 – The AutomatorWP – Automator plugin for no-code automations, webhooks &amp; custom in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5487</guid>
    <pubDate>Sat, 14 Jun 2025 07:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5487</strong></p>
  <p>The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for aut…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-57459 – A time-based SQL injection vulnerability exists in mydetailsstudent.php in the C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-57459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-57459</guid>
    <pubDate>Mon, 02 Jun 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-57459</strong></p>
  <p>A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4396 – The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-base...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4396</guid>
    <pubDate>Tue, 13 May 2025 04:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4396</strong></p>
  <p>The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append ad…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2317 – The Product Filter by WBW plugin for WordPress is vulnerable to time-based SQL I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2317</guid>
    <pubDate>Fri, 04 Apr 2025 06:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2317</strong></p>
  <p>The Product Filter by WBW plugin for WordPress is vulnerable to time-based SQL Injection via the filtersDataBackend parameter in all versions up to, and including, 2.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existin…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2221 – The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2221</guid>
    <pubDate>Fri, 14 Mar 2025 07:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2221</strong></p>
  <p>The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in all versions up to, and including, 1.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1702 – The Ultimate Member – User Profile, Registration, Login, Member Directory, Conte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1702</guid>
    <pubDate>Wed, 05 Mar 2025 12:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1702</strong></p>
  <p>The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 2.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11260 – The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11260</guid>
    <pubDate>Fri, 21 Feb 2025 06:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11260</strong></p>
  <p>The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55460 – A time-based SQL injection vulnerability in the login page of BoardRoom Limited ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55460</guid>
    <pubDate>Tue, 18 Feb 2025 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55460</strong></p>
  <p>A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13496 – The GamiPress – Gamification plugin to reward points, achievements, badges &amp; ran...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13496</guid>
    <pubDate>Wed, 22 Jan 2025 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13496</strong></p>
  <p>The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated at…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13184 – The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13184</guid>
    <pubDate>Sat, 18 Jan 2025 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13184</strong></p>
  <p>The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including, 3.0.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries int…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0308 – The Ultimate Member – User Profile, Registration, Login, Member Directory, Conte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0308</guid>
    <pubDate>Sat, 18 Jan 2025 06:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0308</strong></p>
  <p>The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for un…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11939 – The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11939</guid>
    <pubDate>Wed, 08 Jan 2025 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11939</strong></p>
  <p>The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ parameter in all versions up to, and including, 3.2.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existin…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11912 – The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind ti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11912</guid>
    <pubDate>Wed, 18 Dec 2024 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11912</strong></p>
  <p>The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id’ parameter in all versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already e…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10247 – The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10247</guid>
    <pubDate>Fri, 06 Dec 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10247</strong></p>
  <p>The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access a…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9887 – The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9887</guid>
    <pubDate>Sat, 16 Nov 2024 10:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9887</strong></p>
  <p>The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.15.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above,…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10645 – The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10645</guid>
    <pubDate>Sat, 16 Nov 2024 09:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10645</strong></p>
  <p>The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-10687 – The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Galler...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10687</guid>
    <pubDate>Tue, 05 Nov 2024 10:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-10687</strong></p>
  <p>The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and including, 24.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8757 – The WP Post Author – Boost Your Blog&amp;#039;s Engagement with Author Box, Social L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8757</guid>
    <pubDate>Sat, 12 Oct 2024 10:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8757</strong></p>
  <p>The WP Post Author – Boost Your Blog&#039;s Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_user_id parameter in all versions up to, and including, 3.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient p…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-9201 – The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9201</guid>
    <pubDate>Thu, 10 Oct 2024 11:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-9201</strong></p>
  <p>The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9018 – The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9018</guid>
    <pubDate>Tue, 01 Oct 2024 09:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9018</strong></p>
  <p>The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to ap…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9130 – The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9130</guid>
    <pubDate>Fri, 27 Sep 2024 06:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9130</strong></p>
  <p>The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.16.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with GiveWP Manager-level access and…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-8503 – An unauthenticated attacker can leverage a time-based SQL injection vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8503</guid>
    <pubDate>Tue, 10 Sep 2024 20:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-8503</strong></p>
  <p>An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7717 – The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7717</guid>
    <pubDate>Sat, 31 Aug 2024 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7717</strong></p>
  <p>The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL que…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7607 – The Front End Users plugin for WordPress is vulnerable to time-based SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7607</guid>
    <pubDate>Thu, 29 Aug 2024 11:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7607</strong></p>
  <p>The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.2.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL quer…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-43360 – ZoneMinder is a free, open source closed-circuit television software application...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43360</guid>
    <pubDate>Mon, 12 Aug 2024 21:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-43360</strong></p>
  <p>ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7548 – The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7548</guid>
    <pubDate>Thu, 08 Aug 2024 06:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7548</strong></p>
  <p>The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and including, 4.2.6.9.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to appen…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7150 – The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7150</guid>
    <pubDate>Thu, 08 Aug 2024 06:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7150</strong></p>
  <p>The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.2.57 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to app…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-6338 – The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6338</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6338</guid>
    <pubDate>Fri, 19 Jul 2024 08:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-6338</strong></p>
  <p>The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append ad…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6338">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6457 – The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6457</guid>
    <pubDate>Tue, 16 Jul 2024 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6457</strong></p>
  <p>The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ‘woof_author’ parameter in all versions up to, and including, 1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL qu…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5792 – The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5792</guid>
    <pubDate>Wed, 10 Jul 2024 02:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5792</strong></p>
  <p>The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Custom-level (seller) access and above, to append additional S…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-6166 – The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6166</guid>
    <pubDate>Tue, 09 Jul 2024 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-6166</strong></p>
  <p>The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contri…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6172 – The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6172</guid>
    <pubDate>Tue, 02 Jul 2024 07:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6172</strong></p>
  <p>The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthen…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6265 – The UsersWP – Front-end login form, User Registration, User Profile &amp; Members Di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6265</guid>
    <pubDate>Sat, 29 Jun 2024 05:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6265</strong></p>
  <p>The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-1839 – Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated bli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1839</guid>
    <pubDate>Wed, 26 Jun 2024 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-1839</strong></p>
  <p>Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate data, or manipulate the database.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6028 – The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6028</guid>
    <pubDate>Tue, 25 Jun 2024 09:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6028</strong></p>
  <p>The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries th…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6027 – The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6027</guid>
    <pubDate>Fri, 21 Jun 2024 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6027</strong></p>
  <p>The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘conditions’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into alread…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-5756 – The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5756</guid>
    <pubDate>Fri, 21 Jun 2024 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-5756</strong></p>
  <p>The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthen…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5605 – The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5605</guid>
    <pubDate>Thu, 20 Jun 2024 04:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5605</strong></p>
  <p>The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with contributor-level access…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5543 – The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5543</guid>
    <pubDate>Wed, 12 Jun 2024 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5543</strong></p>
  <p>The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL que…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-35305 – Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorizat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35305</guid>
    <pubDate>Mon, 10 Jun 2024 15:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-35305</strong></p>
  <p>Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4902 – The Tutor LMS – eLearning and online course solution plugin for WordPress is vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4902</guid>
    <pubDate>Fri, 07 Jun 2024 05:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4902</strong></p>
  <p>The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘course_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with admin access and above, to ap…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5207 – The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Del...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5207</guid>
    <pubDate>Thu, 30 May 2024 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5207</strong></p>
  <p>The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the selected parameter in all versions up to, and including, 2.9.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authent…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-4443 – The Business Directory Plugin – Easy Listing Directories for WordPress plugin fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4443</guid>
    <pubDate>Wed, 22 May 2024 06:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-4443</strong></p>
  <p>The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4318 – The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4318</guid>
    <pubDate>Thu, 16 May 2024 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4318</strong></p>
  <p>The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Instructor-level permissions and above, to append additional SQL queri…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-4434 – The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4434</guid>
    <pubDate>Tue, 14 May 2024 15:43:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-4434</strong></p>
  <p>The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3055 – The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3055</guid>
    <pubDate>Tue, 14 May 2024 15:39:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3055</strong></p>
  <p>The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with contributor acce…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1173 – The WP ERP | Complete HR solution with recruitment &amp; job listings | WooCommerce ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1173</guid>
    <pubDate>Thu, 02 May 2024 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1173</strong></p>
  <p>The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.13.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1893 – The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1893</guid>
    <pubDate>Tue, 09 Apr 2024 19:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1893</strong></p>
  <p>The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, 3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with contributor access and above, to append…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0952 – The WP ERP | Complete HR solution with recruitment &amp; job listings | WooCommerce ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0952</guid>
    <pubDate>Tue, 09 Apr 2024 19:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0952</strong></p>
  <p>The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.12.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0913 – The WP ERP | Complete HR solution with recruitment &amp; job listings | WooCommerce ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0913</guid>
    <pubDate>Fri, 29 Mar 2024 07:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0913</strong></p>
  <p>The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the erp/v1/accounting/v1/transactions/sales REST API endpoint in all versions up to, and including, 1.13.0 due to insufficient escaping on the user supplied status and customer_id parameters and lack of sufficient preparation on the ex…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1751 – The Tutor LMS – eLearning and online course solution plugin for WordPress is vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1751</guid>
    <pubDate>Wed, 13 Mar 2024 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1751</strong></p>
  <p>The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with subscriber/student access or…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0786 – The Conversios – Google Analytics 4 (GA4), Meta Pixel &amp; more Via Google Tag Mana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0786</guid>
    <pubDate>Wed, 28 Feb 2024 09:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0786</strong></p>
  <p>The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ee_syncProductCategory function using the parameters conditionData, valueData, productArray, exclude and include in all versions up to, and including, 7.0.7 due to insufficient escaping on the user supplied parameter and lack of…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22406 – Shopware is an open headless commerce platform. The Shopware application API con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22406</guid>
    <pubDate>Tue, 16 Jan 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22406</strong></p>
  <p>Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in the “aggregations” object. The ‘name’ field in this “aggregations” object is vulnerable SQL-injection and can be exploi…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-6567 – The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6567</guid>
    <pubDate>Thu, 11 Jan 2024 09:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-6567</strong></p>
  <p>The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that ca…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5203 – The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 doe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5203</guid>
    <pubDate>Tue, 26 Dec 2023 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5203</strong></p>
  <p>The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2841 – The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2841</guid>
    <pubDate>Wed, 22 Nov 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2841</strong></p>
  <p>The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in versions up to, and including, 1.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers with admin-level privileges to append additional SQL querie…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3023 – The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3023</guid>
    <pubDate>Wed, 12 Jul 2023 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3023</strong></p>
  <p>The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versions up to, and including, 5.4.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with administrator-level or above permissions, to append additional SQL quer…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36284 – An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36284</guid>
    <pubDate>Fri, 23 Jun 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36284</strong></p>
  <p>An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2607 – The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2607</guid>
    <pubDate>Fri, 09 Jun 2023 06:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2607</strong></p>
  <p>The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrator privileges to append additional SQL qu…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2484 – The Active Directory Integration plugin for WordPress is vulnerable to time-base...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2484</guid>
    <pubDate>Fri, 09 Jun 2023 06:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2484</strong></p>
  <p>The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers with administrator privileges to append additional S…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0895 – The WP Coder – add custom html, css and js code plugin for WordPress is vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0895</guid>
    <pubDate>Fri, 17 Feb 2023 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0895</strong></p>
  <p>The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers with administrative privileges to append additional…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0895">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
