Tag: sqli
26 entries tagged sqli, latest activity first.
- CVE-2026-61425, Balbooa Gridbox for Joomla: a client-supplied cookie is accepted as proof of identity, giving anonymous Super User access
- GeoServer CVE-2026-76904: an unauthenticated SQL injection in the jsonArrayContains filter was exploited within hours of disclosure, before a patch existed, and NCSC-CH put it in front of Swiss operators
- Metabase CVE-2026-72898: an unauthenticated SQL-injection zero-day gave attackers administrator access to BI instances, exploited since at least 3 August, fifteen downstream victims confirmed
- Qbusoft's Medyc practice-management software, used by Polish healthcare providers, is breached via SQL injection, and Zaufana Trzecia Strona attributes it to the actor behind August's MyDr leak
- CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
- CVE-2026-76461: Cisco Secure Email Gateway unauthenticated SQL injection in email parsing reaches root command execution, exploited before disclosure (CVSS 9.8)
- Association des maires de France confirms a UNION-based SQL-injection breach exposing 114,000 records on mayors, municipal councillors and territorial agents, plaintext passwords included
- CVE-2026-9586, Sangoma Switchvox: an unauthenticated XML phone-notification endpoint reaches PostgreSQL COPY TO PROGRAM, and honeypots caught exploitation nearly seven weeks after the patch shipped
- CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876, ServiceNow AI Platform: three unauthenticated CVSS 10.0 flaws plus a related Now Platform sandbox escape
- Zalktis (Latvian accounting software): unauthenticated SQL injection reachable by any PEPPOL/UBL e-invoice sender, no account, no network position, just a routine bookkeeping import (CVE-2026-59109)
- iCagenda Calendar module for Joomla: unauthenticated SQL injection via com_ajax needs no session, token or account (CVE-2026-67365, CVSS 9.2), and the vulnerable module's own version number does not track the package version
- YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137), out-of-band 7.0.2 patch, exploited within days and KEV-listed
- Adobe Campaign Classic APSB26-120, three more unauthenticated CVSS 10.0 code-execution flaws, and last week's build 9398 is the version they affect
- Veeam Service Provider Console and Veeam ONE, ten CVEs, headed by an unauthenticated CVSS 10.0 remote code execution on the Veeam ONE agent host
- CVE-2026-54363 and five siblings, Gladinet CentreStack: one cryptographic key shared across every installation forges a domain-administrator token, completing an unauthenticated RCE chain
- CVE-2026-48449, Adobe Campaign Classic: an authorization flaw gives unauthenticated arbitrary code execution (CVSS 10.0), on-premise and hybrid deployments only
- CVE-2026-65766 and CVE-2026-65879, SP Page Builder for Joomla: a CSRF token Joomla hands to anonymous visitors is the only guard on an ORDER BY injection, plus a shipped-in-source shared secret that opens a mail relay
- GLPI 11.0.8 / 10.0.26, critical RCE via form import and complete MFA bypass in the public-sector ITSM platform
- Ubiquiti UniFi SAB-066, 25 vulnerabilities incl. unauthenticated CVSS 10.0 command injection in UniFi Connect (CVE-2026-50746)
- CVE-2026-59509, cve-search: unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes (CVSS 9.2)
- CVE-2026-57517, Control Web Panel: pre-auth blind SQL injection to web-shell RCE (CVSS 9.8)
- CVE-2026-12789, ILIAS 11.0: unpatched, PoC-public SQL injection in the learning-progress subsystem (DACH education exposure)
- Check Point chains SQL injection to RCE in LangGraph's checkpointer (CVE-2025-67644 + CVE-2026-28277)
- Mautic 7.1.2 / 6.0.9, seven authenticated flaws, including two post-auth RCE paths (SSTI and path-traversal-to-PHP-RCE), an SSRF and an API authorization bypass
- ILIAS LMS, nine fixes shipped 2026-05-27, two critical access-control gaps (CVSS 9.8 + 9.3), NCSC.ch flags SOAP interface as primary unauthenticated attack surface