Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,915 CVEs tagged with CWE-894,433 Critical, 8,389 High, 6,143 Medium, 949 Low, 1 Unrated.

CVE-2026-11776

Published Jun 18, 2026

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions…

CVSS 4.9 · Medium
evidence mentions
11
Buzz score
36.4

CVE-2026-11360

Published Jun 18, 2026

The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_direction' parameter in all versions up to, and including, 4.0.…

CVSS 4.9 · Medium
evidence mentions
15
Buzz score
39.2

CVE-2026-10736

Published Jun 18, 2026

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 3.9…

CVSS 4.9 · Medium
evidence mentions
11
Buzz score
36.4

CVE-2026-35069

Published Jun 17, 2026

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privil…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35068

Published Jun 17, 2026

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privil…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54812

Published Jun 17, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection. This issue affects Motors:…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54819

Published Jun 17, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom:…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54818

Published Jun 17, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects…

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54815

Published Jun 17, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection.…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54813

Published Jun 17, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects Sur…

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54809

Published Jun 17, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: fro…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54808

Published Jun 17, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-59554

Published Jun 17, 2026

Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.

CVSS 9.3 · Critical

CVE-2026-54811

Published Jun 17, 2026

Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54187

Published Jun 17, 2026

Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54186

Published Jun 17, 2026

Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54185

Published Jun 17, 2026

Subscriber SQL Injection in Cornerstone < 7.8.8 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-49084

Published Jun 17, 2026

Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-49080

Published Jun 17, 2026

Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-49079

Published Jun 17, 2026

Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-49076

Published Jun 17, 2026

Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-49073

Published Jun 17, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Dir…

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-48967

Published Jun 17, 2026

Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-48875

Published Jun 17, 2026

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-39596

Published Jun 17, 2026

Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Showing 476-500 of 19,915 CVEsPage 20 of 797