← Back
CWE-89

20,595 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,595)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jun 16, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is...Show more
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strings prior to json_decode(), which removes the escaping applied by WordPress's wp_magic_quotes; the resulting decoded array values are then concatenated directly into SQL WHERE clauses without parameterization, and the constructed query is executed via $wpdb->get_results() without $wpdb->prepare(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The handler also returns the executed SQL string in its JSON response, which simplifies oracle construction for blind exploitation.Show less
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.5 HIGH· v3
N/A· v2
Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.5 HIGH· v3
N/A· v2
Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.5 HIGH· v3
N/A· v2
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.5 HIGH· v3
N/A· v2
Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.5 HIGH· v3
N/A· v2
Subscriber SQL Injection in GamiPress <= 7.8.7 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.5 HIGH· v3
N/A· v2
Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.