CVE-2026-65569
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
CVSS
8.5
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 6, 2026 · Last modified: Aug 6, 2026 · CWE-89
Not enough EPSS history yet.
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-664479.3 CRI—
———Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.6hCVE-2026-655478.5 HIG—
———Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.6hCVE-2026-655469.3 CRI—
———Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.7hCVE-2026-655209.3 CRI—
———Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.6hCVE-2026-655089.3 CRI—
———Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.6hCVE-2026-34191——
———Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.37h