CVE-2026-65546
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
CVSS
9.3
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 6 ago 2026 · Última mod.: 6 ago 2026 · CWE-89
Sin historial EPSS suficiente todavía.
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-664479.3 CRÍ—
———Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.7hCVE-2026-655698.5 ALT—
———Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.7hCVE-2026-655478.5 ALT—
———Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.7hCVE-2026-655209.3 CRÍ—
———Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.7hCVE-2026-655089.3 CRÍ—
———Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.7hCVE-2026-34191——
———Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.38h