CVE-2026-17017
The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement thr
CVSS
8.1
High
EPSS
0.2%
p13
KEV
—
Exploit Today
4
0-100
Published: Aug 9, 2026 · Last modified: Aug 10, 2026 · CWE-89
0.2%EPSS · 30 days0.2%
2026-08-092026-08-20
The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-76613——
———Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.7hCVE-2026-169596.8 MED—
——0The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.10hCVE-2026-146016.8 MED—
——0The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks.10hCVE-2026-773926.3 MED—
——0A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.12hCVE-2026-687899.9 CRI—
——0Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.11hCVE-2026-687829.9 CRI—
——0Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.7h