CVE-2016-20063
Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by in
CVSS
7.1
High
EPSS
0.2%
p13
KEV
—
Exploit Today
4
0-100
Published: Jun 9, 2026 · Last modified: Jul 21, 2026 · CWE-89
0.2%EPSS · 30 days0.2%
2026-07-232026-08-20
Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attackers can access the admin interface and supply crafted SQL statements in the message parameter to extract sensitive database information including user credentials and site configuration data.
- lenonleite.com.brhttp://lenonleite.com.br/
- targethttp://target/wp-admin/admin.php?page=simple-personal-message-outbox&action=view&message=0%20UNION%20SELECT%201,2.3,name,5,slug,7,8,9,10,11,12%20FROM%20wp_terms%20WHERE%20term_id=1
- wordpress.orghttps://wordpress.org/plugins/simple-personal-message/
- www.exploit-db.comhttps://www.exploit-db.com/exploits/40870
- www.vulncheck.comhttps://www.vulncheck.com/advisories/single-personal-message-wordpress-plugin-sql-injection
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-76613——
———Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.6hCVE-2026-169596.8 MED—
——0The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.9hCVE-2026-146016.8 MED—
——0The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks.9hCVE-2026-773926.3 MED—
——0A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.11hCVE-2026-687899.9 CRI—
——0Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.10hCVE-2026-687829.9 CRI—
——0Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.6h