Tag

#SQL Injection

35 published stories tagged with SQL Injection.

criticalExploited VulnerabilitiesJul 19, 2026·3 min read

Unauthenticated attackers exploit WP2Shell vulnerabilities to achieve remote code execution on WordPress websites

Attackers are actively exploiting two critical vulnerabilities, dubbed "WP2Shell," to take control of WordPress websites.

highExploited VulnerabilitiesJul 15, 2026·2 min read

Automated AI pipeline discovers critical SQL injection vulnerability in Creative Mail WordPress plugin

An automated AI pipeline has discovered a critical blind SQL injection vulnerability in the Creative Mail WordPress plugin.

criticalApplication SecurityMay 8, 2026·4 min read

Brief: LiteLLM Proxy Pre-Authentication SQL Injection Exploited Shortly After Disclosure

LiteLLM disclosed a SQL injection vulnerability in the proxy API key verification path. The project says versions v1.81.16 through v1.83.6 are affected and recommends upgrading to v1.83.10-stable.

criticalApplication SecurityMay 8, 2026·4 min read

Defender Guidance: LiteLLM Proxy Pre-Authentication SQL Injection Exploited Shortly After Disclosure

LiteLLM disclosed a SQL injection vulnerability in the proxy API key verification path. The project says versions v1.81.16 through v1.83.6 are affected and recommends upgrading to v1.83.10-stable.

criticalApplication SecurityMay 8, 2026·4 min read

Detection Notes: LiteLLM Proxy Pre-Authentication SQL Injection Exploited Shortly After Disclosure

LiteLLM disclosed a SQL injection vulnerability in the proxy API key verification path. The project says versions v1.81.16 through v1.83.6 are affected and recommends upgrading to v1.83.10-stable.

criticalApplication SecurityMay 8, 2026·4 min read

Risk Brief: LiteLLM Proxy Pre-Authentication SQL Injection Exploited Shortly After Disclosure

LiteLLM disclosed a SQL injection vulnerability in the proxy API key verification path. The project says versions v1.81.16 through v1.83.6 are affected and recommends upgrading to v1.83.10-stable.

highApplication SecurityMay 8, 2026·4 min read

Brief: CodeAstro Online Classroom SQL Injection Vulnerability Disclosed With Public Exploit

A SQL injection vulnerability in CodeAstro Online Classroom 1.0 affects the /askquery.php component through the squeryx argument, according to the NVD/VulDB record.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: CodeAstro Online Classroom SQL Injection Vulnerability Disclosed With Public Exploit

A SQL injection vulnerability in CodeAstro Online Classroom 1.0 affects the /askquery.php component through the squeryx argument, according to the NVD/VulDB record.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: CodeAstro Online Classroom SQL Injection Vulnerability Disclosed With Public Exploit

A SQL injection vulnerability in CodeAstro Online Classroom 1.0 affects the /askquery.php component through the squeryx argument, according to the NVD/VulDB record.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: CodeAstro Online Classroom SQL Injection Vulnerability Disclosed With Public Exploit

A SQL injection vulnerability in CodeAstro Online Classroom 1.0 affects the /askquery.php component through the squeryx argument, according to the NVD/VulDB record.

highApplication SecurityMay 8, 2026·4 min read

Brief: code-projects Simple Chat System SQL Injection Disclosed in sendMessage.php

A SQL injection vulnerability was disclosed in code-projects Simple Chat System 1.0 affecting sendMessage.php.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: code-projects Simple Chat System SQL Injection Disclosed in sendMessage.php

A SQL injection vulnerability was disclosed in code-projects Simple Chat System 1.0 affecting sendMessage.php.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: code-projects Simple Chat System SQL Injection Disclosed in sendMessage.php

A SQL injection vulnerability was disclosed in code-projects Simple Chat System 1.0 affecting sendMessage.php.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: code-projects Simple Chat System SQL Injection Disclosed in sendMessage.php

A SQL injection vulnerability was disclosed in code-projects Simple Chat System 1.0 affecting sendMessage.php.

highApplication SecurityMay 8, 2026·4 min read

Brief: SourceCodester SUP Online Shopping Wishlist SQL Injection Disclosed

A SQL injection issue was reported in SourceCodester SUP Online Shopping 1.0 affecting wishlist.php through the delwlistid argument.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: SourceCodester SUP Online Shopping Wishlist SQL Injection Disclosed

A SQL injection issue was reported in SourceCodester SUP Online Shopping 1.0 affecting wishlist.php through the delwlistid argument.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: SourceCodester SUP Online Shopping Wishlist SQL Injection Disclosed

A SQL injection issue was reported in SourceCodester SUP Online Shopping 1.0 affecting wishlist.php through the delwlistid argument.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: SourceCodester SUP Online Shopping Wishlist SQL Injection Disclosed

A SQL injection issue was reported in SourceCodester SUP Online Shopping 1.0 affecting wishlist.php through the delwlistid argument.

highApplication SecurityMay 8, 2026·4 min read

Brief: SourceCodester SUP Online Shopping Admin Message SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in SourceCodester SUP Online Shopping 1.0 affecting /admin/message.php through the seenid argument.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: SourceCodester SUP Online Shopping Admin Message SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in SourceCodester SUP Online Shopping 1.0 affecting /admin/message.php through the seenid argument.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: SourceCodester SUP Online Shopping Admin Message SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in SourceCodester SUP Online Shopping 1.0 affecting /admin/message.php through the seenid argument.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: SourceCodester SUP Online Shopping Admin Message SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in SourceCodester SUP Online Shopping 1.0 affecting /admin/message.php through the seenid argument.

highApplication SecurityMay 8, 2026·4 min read

Brief: SourceCodester SUP Online Shopping SQL Injection Found in Admin Reply Message Handler

NVD/VulDB reports a SQL injection issue in SourceCodester SUP Online Shopping 1.0 affecting /admin/replymsg.php through the msgid argument.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: SourceCodester SUP Online Shopping SQL Injection Found in Admin Reply Message Handler

NVD/VulDB reports a SQL injection issue in SourceCodester SUP Online Shopping 1.0 affecting /admin/replymsg.php through the msgid argument.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: SourceCodester SUP Online Shopping SQL Injection Found in Admin Reply Message Handler

NVD/VulDB reports a SQL injection issue in SourceCodester SUP Online Shopping 1.0 affecting /admin/replymsg.php through the msgid argument.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: SourceCodester SUP Online Shopping SQL Injection Found in Admin Reply Message Handler

NVD/VulDB reports a SQL injection issue in SourceCodester SUP Online Shopping 1.0 affecting /admin/replymsg.php through the msgid argument.

highApplication SecurityMay 8, 2026·4 min read

Brief: CodeAstro Leave Management System Login SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in CodeAstro Leave Management System 1.0 affecting /login.php through the txt_username argument.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: CodeAstro Leave Management System Login SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in CodeAstro Leave Management System 1.0 affecting /login.php through the txt_username argument.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: CodeAstro Leave Management System Login SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in CodeAstro Leave Management System 1.0 affecting /login.php through the txt_username argument.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: CodeAstro Leave Management System Login SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in CodeAstro Leave Management System 1.0 affecting /login.php through the txt_username argument.

highApplication SecurityMay 8, 2026·4 min read

Brief: zyx0814 FilePress Shares Filelist API SQL Injection Disclosed

A SQL injection vulnerability was reported in zyx0814 FilePress up to 2.2.0 affecting dzz/shares/admin.php in the Shares Filelist API.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: zyx0814 FilePress Shares Filelist API SQL Injection Disclosed

A SQL injection vulnerability was reported in zyx0814 FilePress up to 2.2.0 affecting dzz/shares/admin.php in the Shares Filelist API.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: zyx0814 FilePress Shares Filelist API SQL Injection Disclosed

A SQL injection vulnerability was reported in zyx0814 FilePress up to 2.2.0 affecting dzz/shares/admin.php in the Shares Filelist API.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: zyx0814 FilePress Shares Filelist API SQL Injection Disclosed

A SQL injection vulnerability was reported in zyx0814 FilePress up to 2.2.0 affecting dzz/shares/admin.php in the Shares Filelist API.

highApplication SecurityMay 8, 2026·4 min read

CodeAstro Online Classroom SQL Injection Vulnerability Disclosed With Public Exploit

A SQL injection vulnerability in CodeAstro Online Classroom 1.0 affects the /askquery.php component through the squeryx argument, according to the NVD/VulDB record.